Ransom

How to remove “Ransom:Win32/Ryuk.AA”?

Malware Removal

The Ransom:Win32/Ryuk.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Ryuk.AA virus can do?

    How to determine Ransom:Win32/Ryuk.AA?

    
    

    File Info:

    crc32: 7ADA92D2
    md5: 91759691cfe41dd1a9dd07eaf9f48129
    name: 91759691CFE41DD1A9DD07EAF9F48129.mlw
    sha1: 37fd2b22f3a9c85cdbaaf4cbbe33333ecc8030c4
    sha256: 58a0a5646669443e997f88d532219141ff6c9ca8d36cd449c34a1807be919a9d
    sha512: f19d0b358f318e243a648311b1cf7e9c162cf18880f667ba4daff3fd5696a17854a091791452ee9814b1e1e85d07f4b98da07d957b7f51b450692e85a6b5e3a6
    ssdeep: 3072:FeIkko3y53/G7kD2px37AQdNKzCqVrlArF02DV/zPS:6I/GwKp1TtuWpLa
    type: PE32+ executable (GUI) x86-64, for MS Windows

    Version Info:

    0: [No Data]

    Ransom:Win32/Ryuk.AA also known as:

    K7AntiVirusTrojan ( 00553fc91 )
    Elasticmalicious (high confidence)
    DrWebTrojan.Encoder.27559
    CynetMalicious (score: 100)
    ALYacTrojan.Ransom.Ryuk
    CylanceUnsafe
    ZillyaTrojan.Generic.Win32.686807
    SangforWin.Ransomware.Ryuk-6688842-0
    CrowdStrikewin/malicious_confidence_100% (W)
    AlibabaRansom:Win32/Filecoder.d75786e0
    K7GWTrojan ( 00553fc91 )
    Cybereasonmalicious.1cfe41
    CyrenW64/Ransom.Ryuk.A.gen!Eldorado
    ESET-NOD32a variant of Win64/Filecoder.Ryuk.A
    APEXMalicious
    AvastWin64:MalwareX-gen [Trj]
    ClamAVWin.Ransomware.Ryuk-6688842-0
    KasperskyHEUR:Trojan.Win32.Generic
    BitDefenderGeneric.Ransom.Ryuk.00FD0BC1
    NANO-AntivirusTrojan.Win64.Encoder.foaeui
    MicroWorld-eScanGeneric.Ransom.Ryuk.00FD0BC1
    TencentWin32.Trojan.Generic.Hron
    Ad-AwareGeneric.Ransom.Ryuk.00FD0BC1
    SophosMal/Generic-R + Troj/Ransom-FAF
    ComodoMalware@#28ent9v7n6os8
    F-SecureHeuristic.HEUR/AGEN.1110011
    VIPRETrojan.Win32.Generic!BT
    TrendMicroRansom.Win64.RYUK.SMTHC
    McAfee-GW-EditionRansom-Ryuk!91759691CFE4
    FireEyeGeneric.mg.91759691cfe41dd1
    EmsisoftGeneric.Ransom.Ryuk.00FD0BC1 (B)
    SentinelOneStatic AI – Suspicious PE
    JiangminTrojan.Generic.dbyfd
    WebrootW32.Rogue.Gen
    AviraHEUR/AGEN.1110011
    Antiy-AVLTrojan[Ransom]/Win32.Ryuk
    MicrosoftRansom:Win32/Ryuk.AA
    ArcabitGeneric.Ransom.Ryuk.00FD0BC1
    AegisLabTrojan.Win32.Generic.4!c
    ZoneAlarmHEUR:Trojan.Win32.Generic
    GDataGeneric.Ransom.Ryuk.00FD0BC1
    AhnLab-V3Malware/Win64.Ransom.C2922646
    Acronissuspicious
    McAfeeRansom-Ryuk!91759691CFE4
    MAXmalware (ai score=100)
    VBA32TrojanRansom.Ryuk
    MalwarebytesRansom.Ryuk
    PandaTrj/CI.A
    TrendMicro-HouseCallRansom.Win64.RYUK.SMTHC
    RisingRansom.Cryptor!8.10A9 (CLOUD)
    YandexTrojan.GenAsa!WycM4bEay84
    IkarusTrojan-Ransom.Ryuk
    MaxSecureTrojan.Malware.7164915.susgen
    FortinetW64/Ryuk.A!tr.ransom
    AVGWin64:MalwareX-gen [Trj]
    Paloaltogeneric.ml
    Qihoo-360Win64/Ransom.Ryuk.H8oA3cUA

    How to remove Ransom:Win32/Ryuk.AA?

    Ransom:Win32/Ryuk.AA removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment