Ransom

Troj/Ransom-GER (file analysis)

Malware Removal

The Troj/Ransom-GER is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Ransom-GER virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Creates an autorun.inf file
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Ransom-GER?


File Info:

crc32: 4F6D0957
md5: d8285f65785d6123f918af5f06b349a2
name: D8285F65785D6123F918AF5F06B349A2.mlw
sha1: eb15c193d4754a2c94e01933ea7e75872b3280b0
sha256: 2bee8d8a13aa860bbad160856fb8182017d88b967d96bab10919c713c39f24bf
sha512: 22e5677780a5cf37963ba4cd2763e55d84be3f06368b23abc3c29499f644a94b8a92401c242fa09e08d16d38c61553084ecaca3c23dfa7cea81b2a39c1b6515b
ssdeep: 12288:2TCEoqITFUyBg3xtezkWa5W/yVuyl7gDcarm/qxLJtcCuhurME6L6ry:2TCEJ+CSg3xtezkWa5IyVb9otm/qxt2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: taskhost.exe
FileVersion: 10.0.17763.831 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.17763.831
FileDescription: Host Process for Windows Tasks
OriginalFilename: taskhost.exe
Translation: 0x0409 0x04b0

Troj/Ransom-GER also known as:

K7AntiVirusTrojan ( 00577dec1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33477
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Avaddon
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.17713
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Avaddon.8c050b01
K7GWTrojan ( 00577dec1 )
Cybereasonmalicious.5785d6
CyrenW32/Ransom.CWIR-0100
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Filecoder.Avaddon.C
ZonerTrojan.Win32.110341
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
KasperskyHEUR:Trojan-Ransom.Win32.Avaddon.gen
BitDefenderGen:Variant.Ransom.Avaddon.3
NANO-AntivirusTrojan.Win32.DelShad.ikjusp
MicroWorld-eScanGen:Variant.Ransom.Avaddon.3
TencentMalware.Win32.Gencirc.10ce3680
Ad-AwareGen:Variant.Ransom.Avaddon.3
SophosTroj/Ransom-GER
ComodoMalware@#1u37ilwhnmyo4
BitDefenderThetaGen:NN.ZexaF.34722.Vu0@aGfdA!fi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.AVADDON.SMTHA
McAfee-GW-EditionTrojan-FTMI!D8285F65785D
FireEyeGeneric.mg.d8285f65785d6123
EmsisoftGen:Variant.Ransom.Avaddon.3 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.DelShad.ayx
AviraHEUR/AGEN.1136765
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.3132C67
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Avaddon.MK!MTB
ArcabitTrojan.Ransom.Avaddon.3
AegisLabTrojan.Win32.DelShad.4!c
GDataGen:Variant.Ransom.Avaddon.3
AhnLab-V3Malware/Win.Ransom.R422799
McAfeeTrojan-FTMI!D8285F65785D
MAXmalware (ai score=83)
VBA32Trojan.DelShad
MalwarebytesRansom.Avaddon
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.AVADDON.SMTHA
RisingRansom.Avaddon!1.C7A8 (CLASSIC)
YandexTrojan.DelShad!/45YM/sUdvI
IkarusTrojan-Ransom.Avaddon
MaxSecureTrojan.Malware.74279478.susgen
FortinetW32/Avaddon.C!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove Troj/Ransom-GER?

Troj/Ransom-GER removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment