Ransom

How to remove “Ransom:Win32/Rantest.A”?

Malware Removal

The Ransom:Win32/Rantest.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Rantest.A virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/Rantest.A?


File Info:

crc32: 32C84133
md5: e46bc87617d4202c6c8e110830ba8423
name: E46BC87617D4202C6C8E110830BA8423.mlw
sha1: f8f0b344f58141c8b42d9f6f9578eefc3077b33d
sha256: f25ce0db83480321d0509403d279e3ccd08fbd9f272277459dcfc0e4cab5382e
sha512: 4139649e29f31b9802f7b409db06435ce19b94a6a4b358c36c11512a9daadeb6a14ae1959ccc266e9a065e142732a891b84a2a91ddc4a42e2583996b45223d60
ssdeep: 6144:X/qurhSW8tTYUd2CCkm/taEFl3g6RswD1f6Wp5VH:XSttT/hm/XFl3fRRUWP
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 KnowBe4 Inc. 2016
Assembly Version: 1.1.0.7
InternalName: StrongCryptorFast.exe
FileVersion: 1.1.0.7
CompanyName: KnowBe4 Inc.
ProductName: Launcher
ProductVersion: 1.1.0.7
FileDescription: Launcher
OriginalFilename: StrongCryptorFast.exe

Ransom:Win32/Rantest.A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Application.RanSim.1
FireEyeGeneric.mg.e46bc87617d4202c
ALYacGen:Application.RanSim.1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005159961 )
BitDefenderGen:Application.RanSim.1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.617d42
CyrenW32/S-7064d619!Eldorado
SymantecHacktool.Cryptran!g2
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Trojan.Generic-6268112-0
KasperskyTrojan-Ransom.MSIL.Sram.x
NANO-AntivirusTrojan.Win32.Ransom.euacir
AegisLabTrojan.MSIL.Sram.j!c
RisingRansom.Sram!8.E107 (CLOUD)
Ad-AwareGen:Application.RanSim.1
EmsisoftGen:Application.RanSim.1 (B)
ComodoTrojWare.MSIL.Ransom.Sram.D@6lklyt
F-SecureHeuristic.HEUR/AGEN.1127299
TrendMicroHT_ZUSY_GF21004F.UVPM
McAfee-GW-EditionGenericRXBT-DN!E46BC87617D4
SophosMal/Generic-S
IkarusTrojan.Win32.Dynamer
GDataGen:Application.RanSim.1
JiangminTrojan.Generic.ebngn
AviraHEUR/AGEN.1127299
Antiy-AVLTrojan/Win32.AGeneric
ArcabitApplication.RanSim.1
SUPERAntiSpywarePUP.RanSim/Variant
ZoneAlarmTrojan-Ransom.MSIL.Sram.x
MicrosoftRansom:Win32/Rantest.A
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.Agent.C2080353
McAfeeGenericRXBT-DN!E46BC87617D4
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesRiskWare.RansomSimulator
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Riskware.KnownBe4.A
TrendMicro-HouseCallHT_ZUSY_GF21004F.UVPM
TencentMalware.Win32.Gencirc.10b443c6
YandexTrojan.Agent!nqzb9Xm8oNk
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Fasem.A!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.e9d

How to remove Ransom:Win32/Rantest.A?

Ransom:Win32/Rantest.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment