Ransom

About “Troj/Ransom-GXM” infection

Malware Removal

The Troj/Ransom-GXM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Ransom-GXM virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering

How to determine Troj/Ransom-GXM?


File Info:

name: 958B8F2E14A2B43DC3C1.mlw
path: /opt/CAPEv2/storage/binaries/0f8e630ab00fd17eb44da0f6078c61804d6a210e7d808c7b7396bbc183d39f76
crc32: FBBF8D6B
md5: 958b8f2e14a2b43dc3c173c7615c5214
sha1: 272b91d2b61b5b8a318e9bee1756feaf0aa79355
sha256: 0f8e630ab00fd17eb44da0f6078c61804d6a210e7d808c7b7396bbc183d39f76
sha512: 4a1d92957adfabdf27b6ac2ced0d13213f6f30bd2dfe131e5a2b6f9dee3f867e9f2d3c5ef9fc45b12acb4659f71f320ff4c7a0d7e0dd9f0c085210f9df5dc191
ssdeep: 3072:IRgv4xDxTxMf1ubjEemRx9gwgRo2o41q8lh8Fuz+WSMzbrsfyb50E3QBSfUqK1Kx:5mxj4uZRJq8wFu1Cyd0E3QMfhqK3cX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17F3405A396E0EF03F23B0E7C33314E0412A469778B8A8555B9FAE7D525A3D20652F5D3
sha3_384: d01fddf05e05526d27c55acb553086501c2aea19dbe4064672d7ed8435d1469bb91dd20a6f1c2fc34c711504023c3ef5
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-10-24 13:15:39

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: NoCry
FileVersion: 1.0.0.0
InternalName: NoCry.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: NoCry.exe
ProductName: NoCry
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Troj/Ransom-GXM also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Heur.Ransom.REntS.Gen.1
Cylanceunsafe
VIPREGen:Heur.Ransom.REntS.Gen.1
Cybereasonmalicious.e14a2b
CyrenW32/MSIL_Troj.ASO.gen!Eldorado
ESET-NOD32a variant of MSIL/Filecoder.AFL
APEXMalicious
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Heur.Ransom.REntS.Gen.1
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
AvastWin32:MalwareX-gen [Trj]
RisingRansom.NoCry!1.D7BF (CLASSIC)
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
F-SecureTrojan.TR/Dropper.Gen
TrendMicroRansom.MSIL.NOCRY.SMLD
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.958b8f2e14a2b43d
SophosTroj/Ransom-GXM
IkarusTrojan-Spy.Keylogger.Snake
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
MicrosoftRansom:MSIL/Cryptolocker.DV!MTB
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Heur.Ransom.REntS.Gen.1
GoogleDetected
AhnLab-V3Ransomware/Win.NoCry.C4805384
MalwarebytesGeneric.Malware.AI.DDS
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.AFL!tr.ransom
BitDefenderThetaGen:NN.ZemsilF.36350.om0@aGOxuGg
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Ransom-GXM?

Troj/Ransom-GXM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment