Ransom

Ransom:Win32/WinPlock removal guide

Malware Removal

The Ransom:Win32/WinPlock is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/WinPlock virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/WinPlock?


File Info:

crc32: 497069B3
md5: 1a11a25fdea8f49f68625016c540c2e2
name: 1A11A25FDEA8F49F68625016C540C2E2.mlw
sha1: 1a648f5b3ce0d34a63e38fb54692fdc35f0a1926
sha256: 122adf6d372cb54a145c95e60c0b3418b114590b4c06feb84b4556f229ca3ad5
sha512: e9342cb2071a9051aa836b39182ade6e36b1de57f5e90c38967a567b9124f3f688cadbc125b212e19acb622f52204593483d189b94e4551c03738873c2e63a4d
ssdeep: 6144:ujPr4CSkRkGUFc2c1rFlkLGVAr0lDu4yvRktOx:kr4CS3JC2clLkLGVXlK5
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

legalcopyright: Nodal
internalname: Outed Valuably
fileversion: 31.68.58.576
legaltrademarks: Humidors Rebills
productname: Sciroccos
productversion: 16.61.34.775
filedescription: Inferno
originalfilename: Arraigner
Translation: 0x0243 0x0249

Ransom:Win32/WinPlock also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4027
MicroWorld-eScanTrojan.Ransom.AQY
ALYacTrojan.Ransom.cryptolocker
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.2055
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.fdea8f
SymantecRansom.Cryptolocker!bm
ESET-NOD32Win32/Filecoder.NFZ
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agentb.bqyo
BitDefenderTrojan.Ransom.AQY
NANO-AntivirusTrojan.Win32.Encoder.earrlx
TencentMalware.Win32.Gencirc.114c368b
Ad-AwareTrojan.Ransom.AQY
SophosMal/Generic-S
ComodoMalware@#h45ztac93qws
BitDefenderThetaGen:NN.ZexaF.34142.smHfa0h7S7pi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Locky-2
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.1a11a25fdea8f49f
EmsisoftTrojan.Ransom.AQY (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.rs
AviraTR/FileCoder.asdfae
Antiy-AVLTrojan/Generic.ASMalwS.1750A42
KingsoftWin32.Troj.Agentb.bq.(kcloud)
MicrosoftRansom:Win32/WinPlock
ArcabitTrojan.Ransom.AQY
GDataTrojan.Ransom.AQY
AhnLab-V3Trojan/Win32.Cryptolocker.C1339919
McAfeeArtemis!1A11A25FDEA8
MAXmalware (ai score=84)
VBA32Trojan.Agentb
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Locky-2
YandexTrojan.GenAsa!dfTA8AsgzGk
IkarusTrojan.Win32.VB
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/WinPlock?

Ransom:Win32/WinPlock removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment