Ransom

How to remove “Ransom:Win32/Tibbar”?

Malware Removal

The Ransom:Win32/Tibbar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Tibbar virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Locates and dumps memory from the lsass.exe process indicative of credential dumping
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Clears Windows events or logs
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com
update.googleapis.com

How to determine Ransom:Win32/Tibbar?


File Info:

crc32: 0E3F7A6B
md5: cbc4c732ab08cce90743f93d41378326
name: CBC4C732AB08CCE90743F93D41378326.mlw
sha1: 7c0cbeeb7419a4e6358995ae0cae558feb7b977d
sha256: 57f5dcee852b7f0be74ec238b743a0b15b9988ca8363958b083350f30b5d2349
sha512: 13c6d726aee1225298d02fc1a5e91d444997213134cc4105546ea318ee19a5caa0f0f958b10a99669683239a9f89592269ffa0ab379ccb05fe95244c222cbb33
ssdeep: 12288:CsBMAvaI6pLbqWRKHZKfErrZJyZ0yqsGO3XR63:1Z6NbqWRwZaEr3yt2O3XR63
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 1996-2017 Adobe Systems Incorporated
InternalName: Adobexae Flashxae Player Installer/Uninstaller 27.0
FileVersion: 27,0,0,170
CompanyName: Adobe Systems Incorporated
LegalTrademarks: Adobexae Flashxae Player
ProductName: Adobexae Flashxae Player Installer/Uninstaller
ProductVersion: 27,0,0,170
FileDescription: Adobexae Flashxae Player Installer/Uninstaller 27.0 r0
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Ransom:Win32/Tibbar also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0051a4151 )
LionicTrojan.Win32.BadRabbit.j!c
DrWebTrojan.BadRabbit.2
CynetMalicious (score: 100)
CAT-QuickHealRansom.BadRabbit.ZZ5
ALYacTrojan.Ransom.BUY
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0051a4151 )
Cybereasonmalicious.2ab08c
BaiduWin32.Trojan.Ransom.b
CyrenW32/BadRabbit.CHEE-5527
SymantecRansom.BadRabbit
ESET-NOD32a variant of Win32/Diskcoder.D
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.BadRabbit.e
BitDefenderTrojan.Ransom.BUY
NANO-AntivirusTrojan.Win32.BadRabbit.fcdusw
MicroWorld-eScanTrojan.Ransom.BUY
TencentMalware.Win32.Gencirc.1149276c
Ad-AwareTrojan.Ransom.BUY
BitDefenderThetaGen:NN.ZexaF.34170.AmNfaCTg9kpi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeTrojan.Ransom.BUY
EmsisoftTrojan.Ransom.BUY (B)
AviraTR/Dropper.wojzr
eGambitransom.BadRabbit
MicrosoftRansom:Win32/Tibbar
GDataTrojan.Ransom.BUY
TACHYONRansom/W32.BadRabbit.441899
McAfeeArtemis!CBC4C732AB08
MAXmalware (ai score=100)
VBA32BScope.Trojan.BadRabbit
MalwarebytesMalware.AI.1642325492
PandaTrj/CI.A
RisingRansom.Diskcoder!1.AE39 (CLASSIC)
YandexTrojan.BadRabbit!I3aE9WRVJJE
IkarusTrojan.Win32.Diskcoder
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Diskcoder.D!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom:Win32/Tibbar?

Ransom:Win32/Tibbar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment