Ransom

Ransom:Win32/Milicry.C!bit (file analysis)

Malware Removal

The Ransom:Win32/Milicry.C!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Milicry.C!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.

How to determine Ransom:Win32/Milicry.C!bit?


File Info:

crc32: 7B801A20
md5: 87fa9d34529aa37d0ff747b6278dd39e
name: 87FA9D34529AA37D0FF747B6278DD39E.mlw
sha1: 7e52a5d3b1396bf70a9d7c32c3f94b525231f59b
sha256: 0eddf1519cb46f821cf90b4ef2b96de054916acb6f26277e6b605ed483b860ce
sha512: 2990c62a81f1ef61bdc4d068cf265892deed0ecf5016ec413d49de70b15961da573631b04169c05a92eaa038b52388d762942dfc5b494dbbbf07d88d293f27f6
ssdeep: 12288:b0kcH5yzNQ0PnlxU3Gd/sW+ZTASDiuVuMTi8A4cQR7daNZe:65yzG8/sBZT7C8TR7GZe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Assembly Version: 2.5.3.2
LegalCopyright: (C)
InternalName: FrmsFieldingx2019s
FileVersion: 2.5.3.2
CompanyName: Oracle Corporation
FileDescription: Searching Suspect Silly Impact Authorized Ushered
LegalTrademarks: (C)
Comments: Searching Suspect Silly Impact Authorized Ushered
ProductName: FrmsFieldingx2019s
Languages: English
ProductVersion: 2.5.3.2
PrivateBuild: 2.5.3.2
OriginalFilename: FrmsFieldingx2019s.exe
Translation: 0x0409 0x04b0

Ransom:Win32/Milicry.C!bit also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.59461
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Sage.Q
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.7076
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Yakes.8fb84e4d
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FQPO
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Yakes.tgzj
BitDefenderTrojan.Ransom.Sage.Q
NANO-AntivirusTrojan.Win32.Yakes.faqlda
MicroWorld-eScanTrojan.Ransom.Sage.Q
TencentMalware.Win32.Gencirc.10bbff55
Ad-AwareTrojan.Ransom.Sage.Q
SophosMal/Generic-S
ComodoMalware@#aa322ld7uw0s
BitDefenderThetaGen:NN.ZexaF.34628.Ku0@a0bu8Efi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_MiliCry-1c
McAfee-GW-EditionGenericRXBP-JT!87FA9D34529A
FireEyeGeneric.mg.87fa9d34529aa37d
EmsisoftTrojan.Ransom.Sage.Q (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.adpt
AviraHEUR/AGEN.1138861
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Milicry.C!bit
ArcabitTrojan.Ransom.Sage.Q
AegisLabTrojan.Win32.Blocker.mDYp
ZoneAlarmTrojan.Win32.Yakes.tgzj
GDataTrojan.Ransom.Sage.Q
AhnLab-V3Win-Trojan/Sagecrypt.Gen
McAfeeGenericRXBP-JT!87FA9D34529A
MAXmalware (ai score=100)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.1388352434
PandaTrj/CI.A
TrendMicro-HouseCallMal_MiliCry-1c
RisingTrojan.Occamy!8.F1CD (CLOUD)
YandexTrojan.Yakes!rMSrWaqllh4
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.FNNB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Botnet.Yakes.HgIASOMA

How to remove Ransom:Win32/Milicry.C!bit?

Ransom:Win32/Milicry.C!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment