Ransom

Ransom:Win32/Rector removal guide

Malware Removal

The Ransom:Win32/Rector is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Rector virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Rector?


File Info:

crc32: B65BE4FB
md5: 3fd143c6b01b8e6ddd3e40b59058a91d
name: 3FD143C6B01B8E6DDD3E40B59058A91D.mlw
sha1: 2afa88fea9d7fab9c10f287c3bf883cb170bd515
sha256: 58a8ec03a3ef35c5480c2d4c62fb95065fbecb8748b661c90e61a4a76014567b
sha512: f2d0c86f04bf29ff930d01908430738d9fbfa46ae76f494d0f3d05693302162367a5c680dae4121756427e76d2c9a8a0face8a0a68f06b8072a98d8a7e1986b7
ssdeep: 24576:ALRElOzg8AJWPoY36JbDxJARmFC/pz/ncemPE9MicW8Qdl1fQg:ALCm5oNJ5XYhzPIM9MicW8IllQg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: ByteScout BarCode Generator Portable
PortableApps.comAppID: ByteScoutBarCodeGeneratorPortable
FileVersion: 7.1.1.1157
PortableApps.comFormatVersion: 2020.07.09
CompanyName: http://forum.portableappc.com/index.php
LegalTrademarks:
Comments: $INSTALLERCOMMENTS
ProductName: ByteScout BarCode Generator Portable
PortableApps.comInstallerVersion: 2020.07.09.0
ProductVersion: 7.1.1.1157
FileDescription: ByteScout BarCode Generator Portable
OriginalFilename: ByteScoutBarCodeGeneratorPortable_7.1.1.1157_English.paf.exe
Translation: 0x0409 0x04b0

Ransom:Win32/Rector also known as:

BkavW32.AIDetect.malware2
ALYacGen:Variant.Bulz.211754
SangforTrojan.Win32.Wacatac.B
BitDefenderGen:Variant.Bulz.211754
Cybereasonmalicious.6b01b8
MicroWorld-eScanGen:Variant.Bulz.211754
Ad-AwareGen:Variant.Bulz.211754
McAfee-GW-EditionBehavesLike.Win32.ICLoader.tc
FireEyeGen:Variant.Bulz.211754
EmsisoftGen:Variant.Bulz.211754 (B)
eGambitUnsafe.AI_Score_86%
MicrosoftRansom:Win32/Rector
ArcabitTrojan.Bulz.D33B2A
AegisLabTrojan.Win32.Bulz.4!c
GDataGen:Variant.Bulz.211754
McAfeeArtemis!3FD143C6B01B
MAXmalware (ai score=87)
VBA32BScope.Trojan.MSIL.Crypt
TrendMicro-HouseCallTROJ_GEN.R002H09ET21
IkarusTrojan.HTML.Redirector

How to remove Ransom:Win32/Rector?

Ransom:Win32/Rector removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment