Ransom Trojan

Trojan-Ransom.Win32.Birele.cy information

Malware Removal

The Trojan-Ransom.Win32.Birele.cy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Birele.cy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Ransom.Win32.Birele.cy?


File Info:

name: FADC3E74A819A94357E7.mlw
path: /opt/CAPEv2/storage/binaries/33df3daa96efc53d475bbf252752b54999620d4e7407f0a4608f83b512ced4cc
crc32: D6611F25
md5: fadc3e74a819a94357e76bd2e7018678
sha1: c5065174dad0c40b59e1dfae515152ea85946b22
sha256: 33df3daa96efc53d475bbf252752b54999620d4e7407f0a4608f83b512ced4cc
sha512: 21067e574c058c047441aea817e7ba3a19c1578ed070d7ead35ca5fcf61b1f32dddfd865c067430a0faa355647495f5d6ae1774fa7306fc9d3845bd7b536e488
ssdeep: 6144:4qb6fE0Zety9DaMseb9TSDCU7Wnlj75tmnLCnIeEF898g4uvsvp1wkw1Lz:Mfoe3b9T2H7Wh5tmnFFqLRvUp1wkEL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA84021F49842F76F2B03739BD48BD2BE36CB372A6DAA20717514E079EB284F5217125
sha3_384: ae44195215947e4ff30bcda56f1af7fddce00c2f92ce3620503d9a117b1f87e3747164588c08107ee200184ce230b93b
ep_bytes: 558bec83c4e88d45ec508d45f4506879
timestamp: 2004-06-29 11:56:33

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Birele.cy also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Birele.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellStartup.yCWaaeZk@ipc
FireEyeGeneric.mg.fadc3e74a819a943
McAfeePWS-Spyeye.fe
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Birele.dc8304b9
K7GWTrojan ( 0055dd191 )
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderThetaAI:Packer.614C5C0A21
VirITTrojan.Win32.Panda.TYG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.JQK
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Birele.cy
BitDefenderGen:Trojan.ShellStartup.yCWaaeZk@ipc
NANO-AntivirusTrojan.Win32.MLW.divts
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
APEXMalicious
TencentWin32.Trojan.Birele.Egye
Ad-AwareGen:Trojan.ShellStartup.yCWaaeZk@ipc
SophosMal/Generic-R + Mal/Zbot-AV
ComodoMalware@#2lb2p7okdm3ws
DrWebTrojan.PWS.Panda.13474
ZillyaTrojan.Kryptik.Win32.888074
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionBehavesLike.Win32.Spyeye.fh
EmsisoftGen:Trojan.ShellStartup.yCWaaeZk@ipc (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ShellStartup.yCWaaeZk@ipc
JiangminTrojan.Birele.o
eGambitGeneric.Malware
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.18A6FC4
ArcabitTrojan.ShellStartup.E78D72
ViRobotTrojan.Win32.A.Birele.358400
MicrosoftRansom:Win32/LockScreen.AO
AhnLab-V3Trojan/Win32.Zbot.R2835
Acronissuspicious
VBA32Trojan.Zeus.EA.0999
ALYacGen:Trojan.ShellStartup.yCWaaeZk@ipc
AvastWin32:Malware-gen
RisingRansom.Birele!8.3094 (CLOUD)
YandexTrojan.Birele!4UicyXSR9uM
IkarusTrojan.Win32.Spyeye
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.NAS!tr
AVGWin32:Malware-gen
Cybereasonmalicious.4a819a
PandaGeneric Malware

How to remove Trojan-Ransom.Win32.Birele.cy?

Trojan-Ransom.Win32.Birele.cy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment