Ransom

Ransom:Win32/Somhoveran!pz (file analysis)

Malware Removal

The Ransom:Win32/Somhoveran!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Somhoveran!pz virus can do?

  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Ransom:Win32/Somhoveran!pz?


File Info:

name: 2B9CDC7DC5ACF58403FF.mlw
path: /opt/CAPEv2/storage/binaries/91b4615859c29bbb8432b344be96228f4cf56f9037f76a49044f3584f6143218
crc32: 09323EA7
md5: 2b9cdc7dc5acf58403ff8cb1f5035d7a
sha1: 9dd1512a157067e5daebb5c520888eace6b42098
sha256: 91b4615859c29bbb8432b344be96228f4cf56f9037f76a49044f3584f6143218
sha512: c04aaf322372ab09c153cb2e6e3fb69dc8da5886246f436db53ca7151ba2cc2c93961e2c7e2e992724c43fc3e1d55a8ad8fb5c300da2c8a13537e0ef61ebf075
ssdeep: 12288:nMSU4joci8M6PW1GVFeFd60DFUyhePYMQxKw:MSUCpM2W1GvgmyePvQxK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10CC42B2E7E83857EC1A231759C1BE66875297D901D2038062BE83D4F4AFC36E6435FDA
sha3_384: 1657eaceb49d71f8b839516c0bddfde02ee9fd466f6a4bbc97a95baf345323e900b6bddee923aeec483fbff0b2ef159e
ep_bytes: 558bec83c4f0b8a05b4500e8e404fbff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Ransom:Win32/Somhoveran!pz also known as:

BkavW32.Common.1261DCA1
LionicTrojan.Win32.Gimemo.tnrZ
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.14393
MicroWorld-eScanGen:Variant.Ransom.Ryuk.93
FireEyeGeneric.mg.2b9cdc7dc5acf584
CAT-QuickHealRansom.Somhoveran.C8
SkyhighBehavesLike.Win32.Generic.hh
McAfeeGenericRXEQ-QT!2B9CDC7DC5AC
MalwarebytesNeshta.Virus.FileInfector.DDS
ZillyaTrojan.Gimemo.Win32.6128
SangforRansom.Win32.Gandcrab_22.se
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Winlock.1075
K7GWTrojan ( 0043daac1 )
K7AntiVirusTrojan ( 0043daac1 )
BitDefenderThetaAI:Packer.E09B6B3A20
VirITTrojan.Win32.Generic.ANGX
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AWI
APEXMalicious
TrendMicro-HouseCallMal_LockScreen
ClamAVWin.Malware.Atus-9659809-0
KasperskyTrojan-Ransom.Win32.Gimemo.cdqu
BitDefenderGen:Variant.Ransom.Ryuk.93
NANO-AntivirusTrojan.Win32.LockScreen.foalcc
SUPERAntiSpywareTrojan.Agent/Gen-Beaugrit
AvastWin32:Agent-ATUS [Trj]
TencentTrojan-Ransom.Win32.Gmie.a
EmsisoftGen:Variant.Ransom.Ryuk.93 (B)
F-SecureTrojan.TR/Strictor.oiuya
VIPREGen:Variant.Ransom.Ryuk.93
TrendMicroMal_LockScreen
Trapminemalicious.moderate.ml.score
SophosTroj/AutoG-KE
IkarusTrojan.Strictor
MAXmalware (ai score=86)
JiangminTrojan/Gimemo.gmy
GoogleDetected
AviraTR/Strictor.oiuya
VaristW32/ShellStartup.A.gen!Eldorado
Antiy-AVLTrojan[Ransom]/Win32.Gimemo.bdvq
Kingsoftmalware.kb.a.911
MicrosoftRansom:Win32/Somhoveran!pz
XcitiumTrojWare.Win32.Ransom.Gimemo.OP@5rbubo
ArcabitTrojan.Ransom.Ryuk.93
ZoneAlarmTrojan-Ransom.Win32.Gimemo.cdqu
GDataWin32.Trojan-Ransom.Gimemo.A
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Gimemo.R78730
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Ransom.Ryuk.93
TACHYONRansom/W32.DP-Gimemo.552448
Cylanceunsafe
PandaTrj/Genetic.gen
RisingRansom.LockScreen!1.AA76 (CLASSIC)
YandexTrojan.GenAsa!lI5wcVyzMzo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.9553181.susgen
FortinetW32/LockScreen.AW!tr
AVGWin32:Agent-ATUS [Trj]
Cybereasonmalicious.dc5acf
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Lockscreen.9e7321c3

How to remove Ransom:Win32/Somhoveran!pz?

Ransom:Win32/Somhoveran!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment