Ransom

Ransom:Win32/Revil (file analysis)

Malware Removal

The Ransom:Win32/Revil is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Revil virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

How to determine Ransom:Win32/Revil?


File Info:

crc32: CEDB3F3D
md5: 5137aa7a96a01b15fb08ba19527a0e12
name: 5137AA7A96A01B15FB08BA19527A0E12.mlw
sha1: 7af4356b46e253de6eee56fc7f7fedc76502337d
sha256: 904bf5f05f3cc1da62ee262f9e088a4401eca3c12de63065d6895b6c2026efa4
sha512: 9ebe235ecc7b2ee271442626e49d7949ad519c9762ff24bd1bfbe3f839588c301f23d0459f480725d653b5f6b91c2acd079bf88c9b0f09725fad125168996d4c
ssdeep: 3072:7u5/w2Q7n0QqWDjav5C9l5wxBjYW/m43zPOIIhwToalU2yWdjweKwKhMOyg/Ie:KQ70QqWSv5Cf5wXjj6FhWUPwYF/Ie
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Revil also known as:

K7AntiVirusTrojan ( 00579f801 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33760
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36628135
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Kryptik.cef11c46
K7GWTrojan ( 00579f801 )
Cybereasonmalicious.b46e25
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKFE
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Gen.aatu
BitDefenderTrojan.GenericKD.36628135
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.36628135
Ad-AwareTrojan.GenericKD.36628135
SophosMal/Generic-R + Mal/EncPk-APW
BitDefenderThetaGen:NN.ZexaF.34670.LyW@aaAtIdhG
McAfee-GW-EditionBehavesLike.Win32.Generic.jz
FireEyeGeneric.mg.5137aa7a96a01b15
EmsisoftTrojan.GenericKD.36628135 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gen.bhp
AviraTR/AD.SodinoRansom.yecpg
MicrosoftRansom:Win32/Revil
ArcabitTrojan.Generic.D22EE6A7
AegisLabTrojan.Win32.Malicious.4!c
GDataWin32.Trojan-Ransom.Sokinokibi.VYIAAL
AhnLab-V3Malware/Win.Reputation.C4403547
Acronissuspicious
McAfeeRDN/Ransom
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.Papras
MalwarebytesMalware.AI.3798929486
PandaTrj/CI.A
RisingRansom.Gen!8.DE83 (CLOUD)
YandexTrojan.Gen!YypqvvABl9k
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.116285366.susgen
FortinetW32/Gen.AATU!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.REvil.HgIASSAA

How to remove Ransom:Win32/Revil?

Ransom:Win32/Revil removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment