Ransom

How to remove “Ransom:Win32/Revil.STA”?

Malware Removal

The Ransom:Win32/Revil.STA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Revil.STA virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Revil.STA?


File Info:

crc32: 14B7AAE0
md5: 8535397007ecb56d666b666c3592c26d
name: 8535397007ECB56D666B666C3592C26D.mlw
sha1: 0912b7cecfbe82d6903a8a0dc421c285480e5caa
sha256: aae6e388e774180bc3eb96dad5d5bfefd63d0eb7124d68b6991701936801f1c7
sha512: 0445eba81e437d2ac04c8a30c71dc7869c4cab5dfaec91ceaa3517ebd084b67cf78328c13ecdad80396e5032e5219f242d038a7e6a07648bf865491cf33098c2
ssdeep: 24576:DvizXxcwKjqd7kHeSyG/z35JCxPKkcIQZfa:0Yg7aBgskXKfa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Revil.STA also known as:

DrWebTrojan.Encoder.33939
CynetMalicious (score: 99)
ALYacDropped:Trojan.GenericKD.36885244
CylanceUnsafe
SangforRansom.Win32.Gen.gen
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRansom:Win32/Revil.2a22cc2d
Cybereasonmalicious.007ecb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKRZ
AvastFileRepMalware
KasperskyHEUR:Trojan-Ransom.Win32.Gen.gen
BitDefenderDropped:Trojan.GenericKD.36885244
MicroWorld-eScanDropped:Trojan.GenericKD.36885244
Ad-AwareDropped:Trojan.GenericKD.36885244
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Revil.R002C0DEC21
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.8535397007ecb56d
EmsisoftMalCert.A (A)
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.dejde
MicrosoftRansom:Win32/Revil.STA
ArcabitTrojan.Generic.D232D2FC
AegisLabTrojan.Win32.Gen.j!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Gen.gen
GDataDropped:Trojan.GenericKD.36885244
McAfeeArtemis!8535397007EC
MAXmalware (ai score=86)
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Revil.R002C0DEC21
RisingRansom.Revil!8.11DFD (CLOUD)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HKRZ!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom:Win32/Revil.STA?

Ransom:Win32/Revil.STA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment