Ransom Trojan

About “Trojan-Ransom.Win32.Coronavi.b” infection

Malware Removal

The Trojan-Ransom.Win32.Coronavi.b is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Coronavi.b virus can do?

  • Authenticode signature is invalid

How to determine Trojan-Ransom.Win32.Coronavi.b?


File Info:

name: 0FA6F36BEDCDBF7EEF67.mlw
path: /opt/CAPEv2/storage/binaries/fdb9654839831030e27c01f3c3611cd2ce37c284dede1fcf249982bcfee35841
crc32: A43D03B7
md5: 0fa6f36bedcdbf7eef6707f2feb92b8a
sha1: fb65054c590871469aa727ec3d02bd6e68d9929a
sha256: fdb9654839831030e27c01f3c3611cd2ce37c284dede1fcf249982bcfee35841
sha512: 9be1a968552bcc039bae32bcbb78cd7b4d899fe90d1d271c429e9255a09ad9466ae7698a96947d40255e485b2a9d6c827ba7328999c3da39acfced5a4cb15fca
ssdeep: 24:ev1GSzrCn4E1F0cO0awphPXm/97PnXmGG+7xvzYg4bmgKVAlq0gcQg6GJ5s32IlE:qzP6O0a2C7PXnGkAsVAMbcQ05s3a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D971426166EE4092F3FB2A753B3605578B7B3C559E75C25C06AD202A4BAFB50CC32B12
sha3_384: 46568e87477ca46e1b05834085c242e5dd9a044b029a69444994d4038aaf5af1ea0623a3eacd7ddb47590472e39a3173
ep_bytes: 558bec515168482040008d45f850ff15
timestamp: 2016-09-19 20:21:17

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Coronavi.b also known as:

LionicTrojan.Win32.Coronavi.j!c
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.326677
VIPREGen:Variant.Zusy.326677
SangforRootkit.Win32.Agent.Gen
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.bedcdb
SymantecHacktool.Rootkit
Elasticmalicious (high confidence)
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Coronavi.b
BitDefenderGen:Variant.Zusy.326677
MicroWorld-eScanGen:Variant.Zusy.326677
AvastFileRepMalware [Trj]
RisingTrojan.Generic@AI.80 (RDML:YSbrdhnfnLI8L2hXBk1ATg)
Ad-AwareGen:Variant.Zusy.326677
TACHYONRansom/W32.Coronavi.3584
EmsisoftGen:Variant.Zusy.326677 (B)
F-SecureTrojan.TR/Rootkit.Gen
DrWebTrojan.Winlock.14409
ZillyaTrojan.Coronavi.Win32.1
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
FireEyeGen:Variant.Zusy.326677
APEXMalicious
GDataGen:Variant.Zusy.326677
JiangminTrojan.Coronavi.a
AviraTR/Rootkit.Gen
Antiy-AVLTrojan/Generic.ASBOL.C621
ArcabitTrojan.Zusy.D4FC15
MicrosoftRansom:Win32/Gansom.AC!MTB
GoogleDetected
AhnLab-V3Malware/Win32.Generic.R372320
McAfeeArtemis!0FA6F36BEDCD
MAXmalware (ai score=87)
VBA32BScope.TrojanRansom.Coronavi
CylanceUnsafe
TencentWin32.Trojan.Coronavi.Agow
IkarusTrojan.Rootkit
MaxSecureTrojan.Malware.82353936.susgen
FortinetW32/Coronavi.B!tr
AVGFileRepMalware [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Ransom.Win32.Coronavi.b?

Trojan-Ransom.Win32.Coronavi.b removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment