Ransom Trojan

Trojan.Ransom.Pyrans.B removal

Malware Removal

The Trojan.Ransom.Pyrans.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Pyrans.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • CAPE detected the PyInstaller malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.Pyrans.B?


File Info:

name: B26ABF7554C66FD0363C.mlw
path: /opt/CAPEv2/storage/binaries/315e9e5efbc9f88ccc978d1a52e4ac6f9b26f7dab4a5aede3d11f2da80d52b14
crc32: 8D699208
md5: b26abf7554c66fd0363c23f92c097885
sha1: 434aefdebdcdc4c9517921dde185d958d1e003f0
sha256: 315e9e5efbc9f88ccc978d1a52e4ac6f9b26f7dab4a5aede3d11f2da80d52b14
sha512: d0a12ed6cfe0ad0161315b11d733f8e2ee8a55cde8770241737fae081dd913596a5a218fc4d46bafe0296d604dd2943b035e1d3c806c03f5cc46867bed31c0ed
ssdeep: 98304:NijTXhFRgeLIlRO5sQIgEzju4/yUZBp1w:8jTV1IG5nIgEXusZB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114F533C3F858581DF5232A3879BBD022F879EE2353CD994F0802F7576565BEAB318618
sha3_384: c4debd473818e1d77d27d688be3bfe69aea2cb2f21dbe64551bb6fc837afa670721655cb310e9f279ea5b4bc8f7f0250
ep_bytes: 60be00b043008dbe0060fcff5789e58d
timestamp: 2018-09-04 14:43:33

Version Info:

0: [No Data]

Trojan.Ransom.Pyrans.B also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Ransom.Pyrans.B
FireEyeGeneric.mg.b26abf7554c66fd0
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeArtemis!B26ABF7554C6
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Filecoder.70a41ae1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.554c66
SymantecML.Attribute.HighConfidence
ESET-NOD32Python/Filecoder.BU
Paloaltogeneric.ml
BitDefenderTrojan.Ransom.Pyrans.B
AvastWin32:Malware-gen
Ad-AwareTrojan.Ransom.Pyrans.B
EmsisoftTrojan.Ransom.Pyrans.B (B)
VIPRETrojan.Ransom.Pyrans.B
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SentinelOneStatic AI – Malicious PE
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
GDataTrojan.Ransom.Pyrans.B
AviraHEUR/AGEN.1215227
ArcabitTrojan.Ransom.Pyrans.B
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C2922497
ALYacTrojan.Ransom.Pyrans.B
MalwarebytesTrojan.Crypt
APEXMalicious
MaxSecureTrojan.Malware.104247514.susgen
FortinetRiskware/Filecoder
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Ransom.Pyrans.B?

Trojan.Ransom.Pyrans.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment