Ransom Trojan

About “Trojan.Ransom.BMX” infection

Malware Removal

The Trojan.Ransom.BMX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BMX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Anomalous binary characteristics

How to determine Trojan.Ransom.BMX?


File Info:

crc32: 3E236CAC
md5: d981b95c75b5a80909f62ed630d1917c
name: D981B95C75B5A80909F62ED630D1917C.mlw
sha1: e1817573ff493fea5dd112e07df975a94d15fc1c
sha256: 298d1834dae0da6bf2c2c222ddb7adc93d0901c341d0617901ecd7642182df0d
sha512: b142e46d670ab4bcf6983921e4054c4cacf3201cc04dd5b6bc73a1ed3dd670315699bf9bf4426cd936b6183fcc9348f235ad595d36e9676f6702e536b755fb0a
ssdeep: 6144:8AsBZYCfbrN34FxL6O8lJeEb2Zc2OZDDP560MgflVztlr4ADw:TFTLL8lKhOZDkgs
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan.Ransom.BMX also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005091cb1 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.51319
CynetMalicious (score: 100)
ALYacTrojan.Ransom.BMX
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Enestedel.63892166
K7GWTrojan ( 005091cb1 )
Cybereasonmalicious.c75b5a
ESET-NOD32a variant of Win32/Injector.DMTB
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Cerber-6995024-0
KasperskyHEUR:Trojan-Ransom.Win32.Zerber.gen
BitDefenderTrojan.Ransom.BMX
NANO-AntivirusTrojan.Win32.DMTB.emvpfi
MicroWorld-eScanTrojan.Ransom.BMX
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.Ransom.BMX
SophosMal/Cerber-Z
ComodoMalware@#xvazpgyqwm6i
BitDefenderThetaGen:NN.ZedlaF.34608.du8@aKtJXFai
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.d981b95c75b5a809
EmsisoftTrojan.Ransom.BMX (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1116898
eGambitGeneric.Malware
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Ransom.BMX
AegisLabTrojan.Win32.Zerber.j!c
ZoneAlarmHEUR:Packed.NSIS.Sod.gen
GDataTrojan.Ransom.BMX
TACHYONRansom/W32.Cerber.268173
AhnLab-V3Trojan/Win32.Cerber.R197151
McAfeeArtemis!D981B95C75B5
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Enestedel
MalwarebytesMalware.AI.3315696997
PandaTrj/CI.A
RisingTrojan.Injector!1.A9D4 (CLASSIC)
YandexTrojan.Injector!qP511x2yRqk
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DMTB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HyoDnZsA

How to remove Trojan.Ransom.BMX?

Trojan.Ransom.BMX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment