Ransom Trojan

Trojan.Ransom.Ranzy removal

Malware Removal

The Trojan.Ransom.Ranzy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Ranzy virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Writes a potential ransom message to disk
  • Clears Windows events or logs
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ransom.Ranzy?


File Info:

crc32: EDA4040C
md5: 2811c797904c1429b9530aae73e393c2
name: 2811C797904C1429B9530AAE73E393C2.mlw
sha1: 20102532dfc58bc8256f507da4a177850f349f7a
sha256: bbf122cce1176b041648c4e772b230ec49ed11396270f54ad2c5956113caf7b7
sha512: 11b022eef9d67efb934243b9097e87cbe13b32abacede43f77ca43825540a08906c059038cd6f9e160bed8d269d7466ec3b767ccde832bea3d07fae1938161ba
ssdeep: 3072:nBTwLMbwf+AKzOvWW5yyIlLGFqKLPV7K9zVnuNkClYA+skh0Gj36Tz:n1SMQ+AyOvWW5yvlL4qsKvuNkiYhh0V
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.Ranzy also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
CAT-QuickHealTrojanransom.Generic
McAfeeGenericRXAA-AA!2811C797904C
CylanceUnsafe
AegisLabTrojan.Win32.Generic.j!c
SangforMalware
K7AntiVirusTrojan ( 005700951 )
BitDefenderGen:Heur.Ransom.REntS.Gen.1
K7GWTrojan ( 005700951 )
Cybereasonmalicious.7904c1
TrendMicroRansom.Win32.THUNDERX.SMTH
CyrenW32/Filecoder.AJ.gen!Eldorado
SymantecRansom.Cryptolocker
APEXMalicious
KasperskyHEUR:Trojan-Ransom.Win32.Generic
AlibabaRansom:Win32/FileCrypter.b16ae39c
NANO-AntivirusTrojan.Win32.DelShad.hxobqh
TencentMalware.Win32.Gencirc.10ce0b4b
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
EmsisoftTrojan.FileCoder (A)
ComodoTrojWare.Win32.Agent.idoml@0
F-SecureHeuristic.HEUR/AGEN.1139218
DrWebTrojan.Encoder.32739
ZillyaTrojan.DelShad.Win32.715
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.2811c797904c1429
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.DelShad.agl
MaxSecureTrojan.Malware.74279478.susgen
AviraHEUR/AGEN.1139218
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.DelShad
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/FileCrypter.MB!MTB
ArcabitTrojan.Ransom.REntS.Gen.1
ViRobotTrojan.Win32.Z.Delshad.142848
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Heur.Ransom.REntS.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransomlock.R353561
BitDefenderThetaGen:NN.ZexaF.34634.iqW@aGj6hDei
ALYacTrojan.Ransom.Ranzy
TACHYONRansom/W32.RanzyLocker.142848
VBA32BScope.Trojan.DelShad
MalwarebytesRansom.Ranzy
ESET-NOD32a variant of Win32/Filecoder.RanzyLocker.A
TrendMicro-HouseCallRansom.Win32.THUNDERX.SMTH
RisingRansom.FileCrypter!8.11F42 (TFE:5:QDsKbiaRKNJ)
IkarusTrojan-Ransom.Ranzylocker
eGambitUnsafe.AI_Score_100%
FortinetW32/Filecoder.7A3E!tr.ransom
WebrootW32.Malware.Gen
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Ransom.793

How to remove Trojan.Ransom.Ranzy?

Trojan.Ransom.Ranzy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment