Ransom

Should I remove “Ransom:Win32/MegaCortex.A”?

Malware Removal

The Ransom:Win32/MegaCortex.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/MegaCortex.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom:Win32/MegaCortex.A?


File Info:

name: FD3EBC8DC312C876FF04.mlw
path: /opt/CAPEv2/storage/binaries/d207a80adb5311737b6d541122aeda0a13f0353334b836af3412340d3730c9eb
crc32: B0868B97
md5: fd3ebc8dc312c876ff048502e79ff8b0
sha1: 39169cb10fffe6b8a599f2d43e64254bd7648cf9
sha256: d207a80adb5311737b6d541122aeda0a13f0353334b836af3412340d3730c9eb
sha512: 059f17edace98bc6f0cd4ca70fd705be571c843846bddfd35320f852c2ba78f04ac3e6a90c4d44fa81d3174d1653622e8d212b0ee0f344f6b8e8f2ceb26df617
ssdeep: 24576:QF78RE7pJSKBUUoyusymwzLAPbUxpKZrLDF2w:s4y7+C3uIwoPbqurLn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E81501017580C132E5F20832557CEBAB893D7D341B755EDBA7E41E2ACE740D2AB32E66
sha3_384: b24c8c2a33825892c78763943d33fcc926b80d5e08bf4dc9992ebc01bfe22e5dbe82ce2beb68533be20c7fce171cdc7c
ep_bytes: e8f2070000e97afeffffcccccccccccc
timestamp: 2019-04-25 21:08:38

Version Info:

0: [No Data]

Ransom:Win32/MegaCortex.A also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.Ransom.CBH
FireEyeGeneric.mg.fd3ebc8dc312c876
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeTrojan-FQUE!FD3EBC8DC312
CylanceUnsafe
VIPRETrojan.Ransom.CBH
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.dc312c
BitDefenderThetaGen:NN.ZexaF.34786.2uX@aqh8kcfi
VirITTrojan.Win32.DownLoad4.SAA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Filecoder.MegaCortex.B
TrendMicro-HouseCallRansom.Win32.CORTEX.SM
ClamAVWin.Ransomware.Megacortex-6978705-1
KasperskyVHO:Backdoor.Win32.Agent.gen
BitDefenderTrojan.Ransom.CBH
AvastWin32:RansomX-gen [Ransom]
Ad-AwareTrojan.Ransom.CBH
EmsisoftTrojan.Ransom.CBH (B)
ZillyaTrojan.Agent.Win32.1096439
TrendMicroRansom.Win32.CORTEX.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SentinelOneStatic AI – Suspicious PE
SophosTroj/Ransom-FJQ
APEXMalicious
GDataTrojan.Ransom.CBH
JiangminBackdoor.Agent.fbd
AviraTR/Agent.aglg
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.592C
ZoneAlarmVHO:Backdoor.Win32.Agent.gen
MicrosoftRansom:Win32/MegaCortex.A
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Ransom.C3209762
VBA32Trojan.Download
ALYacTrojan.Ransom.CBH
MalwarebytesMalware.AI.2696855620
RisingRansom.MegaCortex!1.B5BB (CLASSIC)
YandexTrojan.GenAsa!QlxkxyPq0Bk
IkarusTrojan-Ransom.MegaCortex
AVGWin32:RansomX-gen [Ransom]

How to remove Ransom:Win32/MegaCortex.A?

Ransom:Win32/MegaCortex.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment