Ransom Trojan

How to remove “Trojan.Ransom.BlackCat”?

Malware Removal

The Trojan.Ransom.BlackCat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BlackCat virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the BlackCat malware family
  • Anomalous binary characteristics

How to determine Trojan.Ransom.BlackCat?


File Info:

name: 68099E389D48E23E66F9.mlw
path: /opt/CAPEv2/storage/binaries/d767524e1bbb8d50129485ffa667eb1d379c745c30d4588672636998c20f857f
crc32: 1E71EC85
md5: 68099e389d48e23e66f92fe9bf328a01
sha1: 74845c914cc9525604ff06212f50b99386240183
sha256: d767524e1bbb8d50129485ffa667eb1d379c745c30d4588672636998c20f857f
sha512: 2a21d4382073a1ba985011e5c119b76edee36b3bbb7065da4b85d8303e5349f19430b7f817a36b9250b0570e125536a152a1e178807e86e0d7fe07d6ada6b810
ssdeep: 49152:OscfPWND/yXHzuYVHx+gqc939ypzl0mE3S33Cb7MPN4/RgaJ2wYB:OscfQETVwgp939Yl0JsyHDvwwYB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169E59E47F98356A9CD671A70305EF33AE6314818052D8E67E7F8DD20BA2E7109EC9E1D
sha3_384: b4a230d83a39a78c4147c52bae4c31cbc7648530f4abd610aedeaf550c6dab99d7aaa0f4ba4f2a9c5305f9dce6536e57
ep_bytes: 83ec0cc70538156f0001000000e87e18
timestamp: 2022-01-14 11:44:51

Version Info:

0: [No Data]

Trojan.Ransom.BlackCat also known as:

LionicTrojan.Win32.Generic.j!c
CynetMalicious (score: 100)
CAT-QuickHealRansom.Win32CiR
ALYacTrojan.Ransom.BlackCat
CylanceUnsafe
SangforRansom.Win32.Generic.ky
K7AntiVirusTrojan ( 0058babf1 )
K7GWTrojan ( 0058babf1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Filecoder.OJP
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.BlackCat-9934796-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Fragtor.49451
ViRobotTrojan.Win32.Z.Fragtor.3080704
MicroWorld-eScanGen:Variant.Fragtor.49451
AvastWin32:RansomX-gen [Ransom]
TencentMalware.Win32.Gencirc.11e4376a
Ad-AwareGen:Variant.Fragtor.49451
EmsisoftGen:Variant.Fragtor.49451 (B)
ZillyaTrojan.Filecoder.Win32.21696
TrendMicroRansom.Win32.BLACKCAT.YXCAQZ
McAfee-GW-EditionBehavesLike.Win32.Rootkit.vh
FireEyeGeneric.mg.68099e389d48e23e
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
GDataGen:Variant.Fragtor.49451
JiangminTrojan.Generic.hexya
AviraTR/FileCoder.wmfdn
Antiy-AVLTrojan/Generic.ASMalwS.350C690
ArcabitTrojan.Fragtor.DC12B
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftRansom:Win32/BlackCat.MK!MTB
AhnLab-V3Trojan/Win.Generic.C4834322
McAfeeRansom-BlackCat!68099E389D48
MAXmalware (ai score=83)
VBA32BScope.TrojanRansom.Agent
MalwarebytesMalware.AI.3797928145
TrendMicro-HouseCallRansom.Win32.BLACKCAT.YXCAQZ
RisingRansom.Blackcat!1.DB0B (CLOUD)
YandexTrojan.Filecoder!xelngPyHVrc
FortinetW32/Filecoder.5F85!tr.ransom
BitDefenderThetaGen:NN.ZexaCO.34182.8IW@a09j2ce
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.14cc95
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.10307848.susgen

How to remove Trojan.Ransom.BlackCat?

Trojan.Ransom.BlackCat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment