Ransom

How to remove “Troj/Ransom-CPS”?

Malware Removal

The Troj/Ransom-CPS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Ransom-CPS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Ransom-CPS?


File Info:

crc32: 488C77E7
md5: af2379cc4d607a45ac44d62135fb7015
name: AF2379CC4D607A45AC44D62135FB7015.mlw
sha1: 39b6d40906c7f7f080e6befa93324dddadcbd9fa
sha256: 26b4699a7b9eeb16e76305d843d4ab05e94d43f3201436927e13b3ebafa90739
sha512: 69899c47d0b15f92980f79517384e83373242e045ca696c6e8f930ff6454219bf609e0d84c2f91d25dfd5ef3c28c9e099c4a3a918206e957be806a1c2e0d3e99
ssdeep: 6144:DCyjXhd1mialK+qoNr8PxtZE6x5v+k6f:rjXhd8ZlKOrMZE6x5b6f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Troj/Ransom-CPS also known as:

MicroWorld-eScanTrojan.Ransom.Petya.C
nProtectTrojan/W32.Agent.230912.JI
CAT-QuickHealRansom.Petya.S5
ALYacTrojan.Ransom.Petya
MalwarebytesRansom.Petya
ZillyaTrojan.Petr.Win32.1
CrowdStrikemalicious_confidence_97% (W)
K7GWTrojan ( 004e14a51 )
K7AntiVirusTrojan ( 004e14a51 )
ArcabitTrojan.Ransom.Petya.C
TrendMicroRansom_PETYA.A
CyrenW32/Petya.NREO-5105
SymantecRansom.Petya
ESET-NOD32Win32/Diskcoder.Petya.A
ZonerTrojan.Petya
TheHackerTrojan/Diskcoder.Petya.a
AvastWin32:Malware-gen
ClamAVWin.Trojan.Petya-5637914-0
KasperskyTrojan-Ransom.Win32.Petr.a
BitDefenderTrojan.Ransom.Petya.C
NANO-AntivirusTrojan.Win32.Crypted.ebffer
ViRobotTrojan.Win32.Z.Petya.230912.A[h]
SUPERAntiSpywareRansom.Petya/Variant
TencentWin32.Trojan.Petya.Jbdu
Endgamemalicious (high confidence)
SophosTroj/Ransom-CPS
ComodoTrojWare.Win32.Petya.A
F-SecureTrojan:W32/Petya.A
DrWebTrojan.Ransom.369
VIPRETrojan.Win32.Generic!BT
Invinceavirus.win32.ramnit.j
McAfee-GW-EditionRansom-Petya
EmsisoftTrojan.Ransom.Petya.C (B)
SentinelOnestatic engine – malicious
F-ProtW32/Petya.A
WebrootRansomware.Petya.Gen
AviraTR/Crypt.Xpack.jvzj
Antiy-AVLTrojan/Win32.TGeneric
MicrosoftRansom:Win32/Petya.A
Ad-AwareTrojan.Ransom.Petya.C
AegisLabTroj.Ransom.W32!c
ZoneAlarmTrojan-Ransom.Win32.Petr.a
GDataWin32.Trojan-Ransom.Petya.B
AhnLab-V3Trojan/Win32.Ransom.R177575
McAfeeRansom-Petya
AVwareTrojan.Win32.Generic!BT
PandaTrj/RansomCrypt.E
TrendMicro-HouseCallRansom_PETYA.A
RisingTrojan.Generic (cloud:8G0iAG3P7YV)
YandexTrojan.Petr!
IkarusTrojan.Win32.Diskcoder
FortinetW32/Petr.A!tr
AVGFileCryptor.JMV
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.1.Malware.Gen

How to remove Troj/Ransom-CPS?

Troj/Ransom-CPS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment