Ransom

Ransom:Win32/Somhoveran (file analysis)

Malware Removal

The Ransom:Win32/Somhoveran is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Somhoveran virus can do?

  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Somhoveran?


File Info:

crc32: D7301F6C
md5: 97a022d3e36616c0eb8b010d9da8c004
name: gamesense
sha1: 4f9dfdb345a78c66ecfdbe7eeef83db9761a5ae7
sha256: c3cc1f288dd6a33cc7798689e4262c7e8907749466df6e775842fe9a0cc8acb3
sha512: fbd3087f9cef2567cdce317c195563586d3f27b8ae06e6e3adf8a8c5803f03ae087d4eebd92b4e42d964799707f30124f90914f927f98fd13a8d485a7da098e7
ssdeep: 3072:ZBgjS2GJyRGvl3hF85k+6LLH1zN14GPEdGVM9h9kKhnsE7ax0RkzjEA:ZfMG9RFsULVxbPEdGV0AIsz+RkP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/Somhoveran also known as:

ClamAVWin.Ransomware.Gimemo-6725202-0
FireEyeGeneric.mg.97a022d3e36616c0
CAT-QuickHealRansom.Somhoveran.C8
McAfeeGenericRXAA-AA!97A022D3E366
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.8819
SangforMalware
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Variant.Zusy.190520
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.3e3661
Invinceaheuristic
F-ProtW32/A-32df3ff0!Eldorado
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.AVPY
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
GDataWin32.Trojan-Ransom.Somhoveran.A
KasperskyTrojan-Ransom.Win32.Gimemo.cdqu
AlibabaRansom:Win32/Gimemo.b35ed1a6
NANO-AntivirusTrojan.Win32.Gimemo.foalcc
MicroWorld-eScanGen:Variant.Zusy.190520
RisingTrojan.LockScreen!1.AA76 (CLOUD)
Ad-AwareGen:Variant.Zusy.190520
SophosMal/Generic-S
ComodoMalware@#1j46iqh915xhn
F-SecureTrojan.TR/Strictor.oiuya
DrWebTrojan.Winlock.14393
TrendMicroMal_LockScreen
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.190520 (B)
IkarusTrojan.Strictor
CyrenW32/A-32df3ff0!Eldorado
JiangminTrojan.Gimemo.tj
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Strictor.oiuya
MAXmalware (ai score=82)
Antiy-AVLTrojan[Ransom]/Win32.Gimemo.bdvq
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D2E838
ZoneAlarmTrojan-Ransom.Win32.Gimemo.cdqu
MicrosoftRansom:Win32/Somhoveran
AhnLab-V3Trojan/Win32.RL_Gimemo.R334889
BitDefenderThetaAI:Packer.1A88FD2F20
VBA32TScope.Trojan.Delf
MalwarebytesRansom.Winlock
PandaTrj/Genetic.gen
ESET-NOD32Win32/LockScreen.AWI
TrendMicro-HouseCallMal_LockScreen
TencentRansom.Win32.Gmie.a
YandexTrojan.GreenLock.Gen.UO
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/LockScreen.AW!tr
WebrootW64.Adware.Dealply
AVGWin32:Agent-ATUS [Trj]
AvastWin32:Agent-ATUS [Trj]
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360HEUR/QVM11.1.6860.Malware.Gen

How to remove Ransom:Win32/Somhoveran?

Ransom:Win32/Somhoveran removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment