Ransom

Ransom:Win32/Sorikrypt.A removal tips

Malware Removal

The Ransom:Win32/Sorikrypt.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Sorikrypt.A virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Sorikrypt.A?


File Info:

crc32: 0B2047BD
md5: d54d2a216e637bcd36e5217cfba98896
name: upload_file
sha1: 41e846d00379083a988db6028890233b4d74e8f4
sha256: d620778dbbcf11e3a293aeaaebac7b6a9a02e7d8790ca5ffa59bda1e9b9632f4
sha512: b92fdfd0ec1cbbfc4145465b88efe75223fb4df2df1d77122527175d211db0d572449726dd9ea8579f7cb4c5dc9df467f5980cb7344b7e931e85a34207f500b3
ssdeep: 6144:XZABbWqsE/Ao+mv8Qv0LVmwq4FU0fNoy6x2UjYe0yIJA94agq/L9j:pANwRo+mv8QD4+0V16x2Y0yIu4agq/Lt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: hack facebook 2019
FileDescription: hack facebook 2019 1.00 Installation
FileVersion: 1.00
Comments:
CompanyName: hack facebook 2019
Translation: 0x0409 0x04e4

Ransom:Win32/Sorikrypt.A also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ransom.Boom.1
ALYacTrojan.Ransom.Xorist
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.lmiW
SangforMalware
K7AntiVirusTrojan ( 001f8f911 )
BitDefenderGen:Variant.Ransom.Boom.1
K7GWTrojan ( 001f8f911 )
Cybereasonmalicious.16e637
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.OLL
APEXMalicious
KasperskyTrojan-Ransom.Win32.Xorist.ln
AlibabaRansom:Win32/Xorist.df3c4292
NANO-AntivirusTrojan.Win32.Encoder.flktai
ViRobotDropper.S.Agent.292691
RisingRansom.Sorikrypt!8.8822 (CLOUD)
EmsisoftGen:Variant.Ransom.Boom.1 (B)
ComodoMalware@#38vlyeighbrin
F-SecureTrojan.TR/Ransom.Xorist.EJ
DrWebTrojan.Encoder.94
Invinceaheuristic
FortinetW32/Xorist.EY!tr
FireEyeGeneric.mg.d54d2a216e637bcd
SophosTroj/Ransom-EY
IkarusWorm.VBS.Jenxcus
CyrenW32/Trojan.AKKJ-8756
JiangminTrojan.Xorist.wgc
WebrootW32.Trojan.GenKD
Aviraobject
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=100)
ArcabitTrojan.Ransom.Boom.1
ZoneAlarmTrojan-Ransom.Win32.Xorist.ln
MicrosoftRansom:Win32/Sorikrypt.A
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Xorist.C2916231
McAfeeArtemis!D54D2A216E63
VBA32Hoax.Xorist
PandaTrj/CI.A
TencentWin32.Trojan.Xorist.Wptd
YandexTrojan.Xorist!U2PsEaCnZHE
SentinelOneDFI – Suspicious PE
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
GDataGen:Variant.Ransom.Boom.1
BitDefenderThetaGen:NN.ZemsilF.34138.lm0@aOZ5Juc
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Ransom.62d

How to remove Ransom:Win32/Sorikrypt.A?

Ransom:Win32/Sorikrypt.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment