Malware

How to remove “TjnRansm.Petr.S19961”?

Malware Removal

The TjnRansm.Petr.S19961 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TjnRansm.Petr.S19961 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Mimics the file times of a Windows system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TjnRansm.Petr.S19961?


File Info:

crc32: F86A5649
md5: f4c8f2a6f11778384e82fbca731a28d2
name: F4C8F2A6F11778384E82FBCA731A28D2.mlw
sha1: a5c03bd706b77b25a857c1b5b79ae4bcb5ba0336
sha256: fa5cc1a5553328d1d97be5f8d838ea7abb5e5aa1d66c623c154b7eacc8dca389
sha512: 7bb75147c9efa31d7ee4ea1fb5ea60682822917f8de9d742edf3e2dbb2843621868c151c11740094c67839dbd67ff93a38a8994b1011b860029f41f6dcf3c000
ssdeep: 12288:GaKcFoEk+71t3gNgokByCCfEPQrfaYmFVE3TTs9Vqeai:nAlkUEP7FVwTT8Vqeai
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Windows Rights Management Services Activation for Server Security Processor
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: Windows Rights Management Services Activation for Server Security Processor
OriginalFilename: rmactivate_ssp.exe
Translation: 0x0409 0x04b0

TjnRansm.Petr.S19961 also known as:

K7AntiVirusTrojan ( 004ffb661 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.14977
CynetMalicious (score: 99)
CAT-QuickHealTjnRansm.Petr.S19961
ALYacTrojan.Ransom.BFT
CylanceUnsafe
ZillyaTrojan.Diskcoder.Win32.20
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004ffb661 )
Cybereasonmalicious.6f1177
SymantecTrojan.Randsom.A
ESET-NOD32a variant of Win32/Diskcoder.Petya.D
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Petya-6960742-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.BFT
NANO-AntivirusTrojan.Win32.Diskcoder.eravux
MicroWorld-eScanTrojan.Ransom.BFT
TencentMalware.Win32.Gencirc.10b0cbe0
Ad-AwareTrojan.Ransom.BFT
ComodoTrojWare.Win32.Ransom.Petya.D@6mmj4l
BitDefenderThetaGen:NN.ZexaF.34142.zq0@a4sEqDki
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_PETYA.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.f4c8f2a6f1177838
EmsisoftTrojan.Ransom.BFT (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Petr.e
AviraHEUR/AGEN.1122319
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1D15836
MicrosoftHackTool:Win32/PowerSploit.A
ArcabitTrojan.Ransom.BFT
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.Petya.T
AhnLab-V3Trojan/Win32.Petr.C3170141
McAfeeRansom-GoldnEye!F4C8F2A6F117
MAXmalware (ai score=99)
VBA32Trojan.MBRlock
MalwarebytesRansom.Petya
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_PETYA.SM1
RisingTrojan.Generic@ML.100 (RDML:MJKuCMyHU6gApCL20UHOrw)
IkarusTrojan.Win32.Diskcoder
FortinetW32/Petya.D!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove TjnRansm.Petr.S19961?

TjnRansm.Petr.S19961 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment