Ransom

Ransom:Win32/RagnarLocker.BM!MSR information

Malware Removal

The Ransom:Win32/RagnarLocker.BM!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/RagnarLocker.BM!MSR virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/RagnarLocker.BM!MSR?


File Info:

crc32: 3542F80A
md5: b1fe6b848f4a08141689896354dd4ec0
name: B1FE6B848F4A08141689896354DD4EC0.mlw
sha1: 7976a9f16c0bb3eff3abf51932b2f433bca4d162
sha256: 6edc6154834951ffc012f575e2827da8e4aca4f67f24ef59a678e02dc40c9c91
sha512: 5801bb61c368523dbee631d5c02a9c7c6ce2ea0954406f833864cc9f48e2f46c14ff31c64b4d4ddd1b6e05d6a769a3b32e5cb9b6682e4e5c70d776ce3d34b072
ssdeep: 3072:uHIFZ+3WqeGplGI26i9L409Ku09NcVkb:r8WqeGplZ4Lu9U
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Ransom:Win32/RagnarLocker.BM!MSR also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052964f1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.32719
CynetMalicious (score: 85)
ALYacDeepScan:Generic.Ransom.Ragnar.1F48D654
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.48f4a0
SymantecRansom.RagnarLocker
ESET-NOD32a variant of Win32/Filecoder.RagnarLocker.A
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Exploit.CVE_2017_0213-6306933-0
BitDefenderDeepScan:Generic.Ransom.Ragnar.1F48D654
NANO-AntivirusTrojan.Win32.Cryptor.hykkdo
MicroWorld-eScanDeepScan:Generic.Ransom.Ragnar.1F48D654
Ad-AwareDeepScan:Generic.Ransom.Ragnar.1F48D654
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34670.qqW@ayEH9Sei
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.b1fe6b848f4a0814
EmsisoftDeepScan:Generic.Ransom.Ragnar.1F48D654 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Cryptor.sl
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_94%
MicrosoftRansom:Win32/RagnarLocker.BM!MSR
ArcabitDeepScan:Generic.Ransom.Ragnar.1F48D654
GDataDeepScan:Generic.Ransom.Ragnar.1F48D654
Acronissuspicious
McAfeeArtemis!B1FE6B848F4A
MAXmalware (ai score=82)
VBA32BScope.Trojan.DelShad
MalwarebytesMalware.AI.4267738065
PandaTrj/GdSda.A
RisingRansom.Ragnar!1.C24D (TFE:dGZlOgRPAFim1adKlw)
IkarusPacker.Win32.Krap
FortinetW32/RagnarLocker.4C9D!tr.ransom
AVGWin32:Trojan-gen
Qihoo-360HEUR/QVM19.1.62DF.Malware.Gen

How to remove Ransom:Win32/RagnarLocker.BM!MSR?

Ransom:Win32/RagnarLocker.BM!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment