Ransom

Ransom:Win64/Satwancrypt removal tips

Malware Removal

The Ransom:Win64/Satwancrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win64/Satwancrypt virus can do?

  • Anomalous binary characteristics

How to determine Ransom:Win64/Satwancrypt?


File Info:

crc32: C82747DB
md5: af48779f4a79051e7b5525a992bd7fdc
name: AF48779F4A79051E7B5525A992BD7FDC.mlw
sha1: 465e3daa9df6f3f4bd012e65c9a4e1ca12492228
sha256: 6a8f08a1834df5e570ca8eee30fbeae90942423fb3b55e23ac362f6cb1fda827
sha512: 839d54239142aba908f7fe2cbea735f1b9fe8a63bad136f102c682598f40ec1968b95e20cded3c5adb11a8b717c065a4867430318324172c036512aa8087e8f6
ssdeep: 1536:alyXZixVlATYPtjXLJzPiSRfYoWUuvAO4a0ySRSntC:7XZixETclXNr17DOFkSng
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

0: [No Data]

Ransom:Win64/Satwancrypt also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.65180
FireEyeGeneric.mg.af48779f4a79051e
ALYacGen:Variant.Cerbu.65180
CylanceUnsafe
BitDefenderGen:Variant.Cerbu.65180
Cybereasonmalicious.f4a790
APEXMalicious
AvastWin64:Evo-gen [Susp]
ClamAVWin.Trojan.Ulise-9794347-0
RisingRansom.Satwancrypt!8.EDEF (TFE:3:SlOAm4Jry7P)
Ad-AwareGen:Variant.Cerbu.65180
EmsisoftTrojan.Injector (A)
F-SecureHeuristic.HEUR/AGEN.1102636
DrWebTrojan.Packed2.39908
ZillyaTrojan.Injector.Win64.18
SophosML/PE-A + Troj/Agent-AWOX
IkarusTrojan.Win64.Injector
JiangminWebToolbar.Generic.afy
AviraHEUR/AGEN.1102636
Antiy-AVLRiskWare[WebToolbar]/Win32.AGeneric
MicrosoftRansom:Win64/Satwancrypt
ArcabitTrojan.Cerbu.DFE9C
GDataGen:Variant.Cerbu.65180
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win64.RL_Crypted.R360221
Acronissuspicious
MAXmalware (ai score=81)
MalwarebytesRansom.Satan
ESET-NOD32a variant of Win64/Injector.F
TencentMalware.Win32.Gencirc.10b77afb
YandexTrojan.GenAsa!EvSp1KH6imM
SentinelOneStatic AI – Malicious PE – Ransomware
FortinetW64/Injector.F!tr
AVGWin64:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom:Win64/Satwancrypt?

Ransom:Win64/Satwancrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment