Ransom

Ransom:Win32/Reveton.R malicious file

Malware Removal

The Ransom:Win32/Reveton.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Reveton.R virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Reveton.R?


File Info:

crc32: CF450EC0
md5: 7aca636bc0e45733bbad6221b79d3946
name: 7ACA636BC0E45733BBAD6221B79D3946.mlw
sha1: effaa9e68f626d5ec24141fc76ec57d5deeea779
sha256: f10ae7635306451e88d6b05c5d95b7e06d757d41e3eb220d559abadda3cd0464
sha512: 1c20bcd8648d599ba34dd56c858adc8fa3eb0d6bdb01fe4bf268b33126b5a27ac4dfb9588507c12427ef75d765bc476a3a96086771dbea9ba3a47b8c6a350ba4
ssdeep: 3072:vjsZjP6aMFKHh9SWT1qS3Nip2F0MbchxnONHK2UlaaI:voRipjW5qEF02cyNq0a
type: MS-DOS executable

Version Info:

0: [No Data]

Ransom:Win32/Reveton.R also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Winlock.8826
MicroWorld-eScanGen:Variant.Fugrafa.105822
FireEyeGeneric.mg.7aca636bc0e45733
ALYacGen:Variant.Fugrafa.105822
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Pincav.kZ0E
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0044533d1 )
BitDefenderGen:Variant.Fugrafa.105822
K7GWTrojan ( 0044533d1 )
Cybereasonmalicious.bc0e45
BitDefenderThetaGen:NN.ZelphiF.34590.rmW@aulkGho
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Reveton.R
TrendMicro-HouseCallTROJ_REVETON.UD
AvastWin32:Reveton-BN [Trj]
ClamAVWin.Trojan.Reveton-9677926-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.RiskGen.btkchj
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareGen:Variant.Fugrafa.105822
SophosML/PE-A + Mal/Emogen-Y
ComodoTrojWare.Win32.Reveton.U@566yty
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroTROJ_REVETON.UD
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dt
EmsisoftGen:Variant.Fugrafa.105822 (B)
IkarusTrojan.Win32.Reveton
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Ransom]/Win32.Foreign
KingsoftWin32.Troj.HrupT.xm.352256.(kcloud)
MicrosoftRansom:Win32/Reveton.R
ArcabitTrojan.Fugrafa.D19D5E
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Fugrafa.105822
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Foreign.C1226009
Acronissuspicious
McAfeeArtemis!7ACA636BC0E4
MalwarebytesMalware.AI.2519438126
PandaTrj/Genetic.gen
APEXMalicious
TencentWin32.Trojan.Generic.Akzi
YandexTrojan.Foreign!J56XY49EDo0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Foreign.DFSO!tr
AVGWin32:Reveton-BN [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.c48

How to remove Ransom:Win32/Reveton.R?

Ransom:Win32/Reveton.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment