Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

Ransom:Win32/Reveton.A information

Published Apr 10, 2024 Ransom category 3 min read
Report context

What to verify before removal

Ransom:Win32/Reveton.A information should be handled as a recovery-sensitive report, not as a routine deletion task. Before removing files, isolate the affected system and compare the detection with the notes below so encrypted data, restore points, and backups are not damaged.

Start by comparing the local file name with 77A62C1602FD57CFA047.mlw, then review the behavior notes for file-encryption activity, ransom notes, renamed documents, and unexpected recovery blockers. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
77A62C1602FD57CFA047.mlw
  • Compare the suspicious file name with 77A62C1602FD57CFA047.mlw.
  • Confirm the detection name matches Ransom:Win32/Reveton.A information before removing related files.
  • Review the report for file-encryption activity, ransom notes, renamed documents, and unexpected recovery blockers so the cleanup is based on observed behavior, not only the label.
  • Disconnect the machine from the network before recovery work and avoid deleting encrypted samples until backups are checked.

The Ransom:Win32/Reveton.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Ransom:Win32/Reveton.A virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Ransom:Win32/Reveton.A?


File Info:

name: 77A62C1602FD57CFA047.mlw
path: /opt/CAPEv2/storage/binaries/b94355b6102533932696d7b920dd3bf399568fad7d735049f070933d4b36f0be
crc32: A0BE8C32
md5: 77a62c1602fd57cfa0476c81f29e204b
sha1: 6122371c05495dfab7e91c94113e87ac40261832
sha256: b94355b6102533932696d7b920dd3bf399568fad7d735049f070933d4b36f0be
sha512: 60e033d8e61f7b98c5a3003fee653ffb27bd4dd9e847c0beb57b9740f2477ed16f08c963d4c9ea61f20851d4381faf85654794d2b43caffed1f4efafc322633f
ssdeep: 6144:BckODmse28IhtKSqm+7BxBOc0M+7ckOgckOKckO:Bjuwpm+7BqcF+7jnjrj
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1C3E56B3AE1818277D16109788E5DA2E8B67F7A301F28645F72DD4F5C8E6B2D1593C2C3
sha3_384: 0351a5fdff2de3cb75c9ca40c5f9ca8cc5f3a604855baa6ac1a320d4ef2a01c83ef4224a37deb0030e39c417833dd56a
ep_bytes: 558becb96e0000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Ransom:Win32/Reveton.A also known as:

Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Pincav.kZ0E
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
FireEye Generic.mg.77a62c1602fd57cf
Skyhigh BehavesLike.Win32.Injector.wz
McAfee GenericRXLZ-GY!77A62C1602FD
Zillya Trojan.Scar.Win32.42860
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Reveton.44207020
K7GW Trojan ( 001ef2ce1 )
K7AntiVirus Trojan ( 001ef2ce1 )
VirIT Trojan.Win32.Generic.BIBX
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 Win32/Losfondup.D
APEX Malicious
ClamAV Win.Trojan.Scar-4577
Kaspersky Trojan.Win32.Scar.hofz
BitDefender Gen:Variant.Zusy.298515
NANO-Antivirus Trojan.Win32.Scar.crsabp
MicroWorld-eScan Gen:Variant.Zusy.298515
Avast Win32:InjectorX-gen [Trj]
Tencent Malware.Win32.Gencirc.115aaa5c
Emsisoft Gen:Variant.Zusy.298515 (B)
F-Secure Trojan.TR/Hijacker.Gen
DrWeb Trojan.MulDrop7.19169
VIPRE Gen:Variant.Zusy.298515
Trapmine malicious.high.ml.score
Sophos Mal/Emogen-Y
Ikarus Trojan.Win32.Reveton
Jiangmin Trojan/Scar.aevc
Google Detected
Avira TR/Hijacker.Gen
Antiy-AVL Trojan/Win32.Scar
Kingsoft Win32.Trojan.Scar.hofz
Microsoft Ransom:Win32/Reveton.A
Xcitium Malware@#2fs6vh8omw3v3
Arcabit Trojan.Zusy.D48E13
ViRobot Trojan.Win32.A.Scar.159744.B
ZoneAlarm Trojan.Win32.Scar.hofz
GData Gen:Variant.Zusy.298515
Varist W32/Hupigon.AU.gen!Eldorado
AhnLab-V3 Trojan/Win32.Scar.C102441
ALYac Gen:Variant.Zusy.298515
MAX malware (ai score=100)
VBA32 Trojan.Scar
Cylance unsafe
Panda Generic Malware
Rising Ransom.Reveton!8.F2 (TFE:4:15QfF6MJnJB)
Yandex Trojan.GenAsa!pnAmY3KrGPo
SentinelOne Static AI – Malicious PE
MaxSecure Trojan.Malware.9439684.susgen
Fortinet W32/Scar.EHXG!tr
AVG Win32:InjectorX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Losfondup.D

How to remove Ransom:Win32/Reveton.A?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.