Ransom

Ransom:Win32/Weenloc removal guide

Malware Removal

The Ransom:Win32/Weenloc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Weenloc virus can do?

  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Ransom:Win32/Weenloc?


File Info:

crc32: 5B887149
md5: 857b78e9a2573697c40952bbaa14e991
name: openallachivementsteamgames.exe
sha1: 30291c102b911e0a68a3c451c565db3e5e22f76a
sha256: 27dcb9a367cfb67c834f95aa889fcf77ba5a26215629d21bf80e3c243cb8ed19
sha512: 5ac82a5c755bbf1a907b1064514eaf9e6a23a83971b35f7f39beb1cc30a7d5d50ba3815c62c19c4a0b76f9f960783a1f6aecc406348a2222baf0d6abebc73757
ssdeep: 6144:sLy84u9nSO2GjZkD10BIY3rb1YfBdfpoZ3u/Ht52w6JSeiFPX5CB:4+u9nx2GjMY3XKfd/H/9PAB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Weenloc also known as:

BkavW32.BitwanX.Trojan
MicroWorld-eScanTrojan.Generic.5848174
FireEyeGeneric.mg.857b78e9a2573697
CAT-QuickHealRansom.Weenloc.A8
Qihoo-360HEUR/QVM05.1.633F.Malware.Gen
ALYacTrojan.Generic.5848174
CylanceUnsafe
VIPRETrojan.Win32.Birele.mby (v)
SangforMalware
K7AntiVirusTrojan ( 0039911e1 )
BitDefenderTrojan.Generic.5848174
K7GWTrojan ( 0039911e1 )
Cybereasonmalicious.9a2573
TrendMicroRansom_WINLOCK.SM
BitDefenderThetaAI:Packer.57603CFA21
F-ProtW32/Trojan2.OAEZ
SymantecTrojan.Ransomlock
ESET-NOD32Win32/LockScreen.AGU
BaiduWin32.Trojan.LockScreen.b
APEXMalicious
AvastWin32:LockScreen-AHV [Trj]
ClamAVWin.Trojan.Fullscreen-41
GDataTrojan.Generic.5848174
KasperskyTrojan-Ransom.Win32.Blocker.jzec
AlibabaRansom:Win32/Blocker.e556b7ed
NANO-AntivirusTrojan.Win32.Fullscreen.crnep
ViRobotTrojan.Win32.A.ChameleonUnlicence.383298
TencentTrojan-Ransom.Win32.Blocker.jzec
Ad-AwareTrojan.Generic.5848174
TACHYONRansom/W32.DP-PornoAsset.407040
SophosMal/Ransom-AI
ComodoTrojWare.Win32.Ransom.Fullscreen.fgt@4t6ar8
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Winlock.3333
ZillyaTrojan.Fullscreen.Win32.35
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.5848174 (B)
IkarusTrojan-Ransom.Fullscreen
CyrenW32/Trojan.GDVD-7096
JiangminTrojan/Fullscreen.ak
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Ransom]/Win32.PornoAsset.cioy
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D593C6E
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
AhnLab-V3Trojan/Win32.Atraps.R214152
ZoneAlarmTrojan-Ransom.Win32.Blocker.jzec
MicrosoftRansom:Win32/Weenloc
CynetMalicious (score: 100)
TotalDefenseWin32/Ransom.PC
McAfeeTrojan-FAZX!857B78E9A257
MAXmalware (ai score=89)
VBA32Hoax.PornoAsset
MalwarebytesTrojan.Winlock
PandaGeneric Malware
ZonerTrojan.Win32.46437
TrendMicro-HouseCallRansom_WINLOCK.SM
RisingTrojan.Win32.Weenloc.a (CLOUD)
YandexTrojan.WinBlock.Black.Gen.AA
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/LockScreen.AGU!tr
AVGWin32:LockScreen-AHV [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.6466044.susgen

How to remove Ransom:Win32/Weenloc?

Ransom:Win32/Weenloc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment