Ransom

Ransom:Win32/Milicry!bit removal

Malware Removal

The Ransom:Win32/Milicry!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Milicry!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Milicry!bit?


File Info:

crc32: 774FE1DF
md5: a7dcb113ea7469420094ca84bb23f3a3
name: A7DCB113EA7469420094CA84BB23F3A3.mlw
sha1: feb336f79c7b0f607500fb69b1a04076b76ad320
sha256: fd5f66f1cf22e7225925076ad87937cf814733e7e3edcfa47e76d547ca7113f2
sha512: 2ceaef00054ef2af675aceb6394a46c384624be934b11779a79618c756b3fd97e1cb18c6a3e90a9230c4835257eda6cb6e6efbcf8c6abf533115abd39726b64c
ssdeep: 6144:h1TMv/l2zVgRKHJWk05wbcaY3exbUsEc8VYvZ98/4cV9Cq:D4/g6U7KwbcaPxYsN8T/4c/Cq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Cinta Software Copyright 2015
CompanyName: Cinta Software
ProductName: Popular
ProductVersion: 1.5.2.192
FileDescription: Precomp Autoexec Afz
OriginalFilename: Popular
Translation: 0x0409 0x04b0

Ransom:Win32/Milicry!bit also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Deliric.26
FireEyeGeneric.mg.a7dcb113ea746942
CAT-QuickHealTrojanDownloader.Upatre
McAfeeArtemis!A7DCB113EA74
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0056e9451 )
BitDefenderGen:Variant.Deliric.26
K7GWTrojan ( 0056e9451 )
Cybereasonmalicious.3ea746
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Upatre.ghda
AlibabaTrojanDownloader:Win32/Upatre.be5a3cf7
NANO-AntivirusTrojan.Win32.Upatre.evevnx
TencentWin32.Trojan-downloader.Upatre.Lpbo
Ad-AwareGen:Variant.Deliric.26
EmsisoftGen:Variant.Deliric.26 (B)
ComodoMalware@#zhlgz0wzsvjr
ZillyaTrojan.Kryptik.Win32.2832461
TrendMicroMal_MiliCry-2t
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosMal/Generic-S
AviraHEUR/AGEN.1102812
MicrosoftRansom:Win32/Milicry!bit
ZoneAlarmTrojan-Downloader.Win32.Upatre.ghda
GDataGen:Variant.Deliric.26
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34804.wC0@am315xci
ALYacGen:Variant.Deliric.26
MAXmalware (ai score=99)
VBA32TrojanDownloader.Upatre
MalwarebytesMalware.AI.2500363740
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.EZQF
TrendMicro-HouseCallMal_MiliCry-2t
RisingRansom.Milicry!8.A2F2 (CLOUD)
YandexTrojan.DL.Upatre!4UNNhqLnA2U
SentinelOneStatic AI – Suspicious PE – Ransomware
FortinetW32/Kryptik.FVJY!tr
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Downloader.0a7

How to remove Ransom:Win32/Milicry!bit?

Ransom:Win32/Milicry!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment