Ransom Trojan

How to remove “UDS:Trojan-Ransom.Win32.Purga”?

Malware Removal

The UDS:Trojan-Ransom.Win32.Purga is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Ransom.Win32.Purga virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

iplogger.com
iplogger.org
ocsp.comodoca.com
ocsp.usertrust.com
crl.usertrust.com
ocsp.sectigo.com

How to determine UDS:Trojan-Ransom.Win32.Purga?


File Info:

crc32: 25C447EA
md5: 18a5a5fae295c5a62d427249d93b3363
name: 18A5A5FAE295C5A62D427249D93B3363.mlw
sha1: a4533ea54effde6727994ea4547a8d28cbb8f4ea
sha256: 05bf8a086e21147175dca22208f36a3dc1dc20dce9fb882d5a419e43556bfc50
sha512: fcffa7d3094eacc3db1e219f820d7afe52b82776dc7f318e6ba45b17372e2fe4234a96bb419ed0ab67de10c729c2ac8f647fd22bfd488acce7688c36ce6cc55a
ssdeep: 1536:NiWIFURqmteReai376ctPV/zNyg/duItuteRlfqFzJBNdsRakYn:5ASai37xPV/L/8quteRlfqFVBNdEakc
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

UDS:Trojan-Ransom.Win32.Purga also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f6e981 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33655
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Amnesia
CylanceUnsafe
ZillyaTrojan.Ransom.Win32.992
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Filecoder.66b26a96
K7GWTrojan ( 004f6e981 )
Cybereasonmalicious.ae295c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyUDS:Trojan-Ransom.Win32.Purga
BitDefenderTrojan.Ransom.Amnesia.C
NANO-AntivirusTrojan.Win32.Filecoder.fcqcwm
MicroWorld-eScanTrojan.Ransom.Amnesia.C
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.Ransom.Amnesia.C
SophosML/PE-A + Mal/DelpDldr-F
ComodoMalware@#2ctkhx8k0e75x
BitDefenderThetaAI:Packer.6B1CE99D1D
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
FireEyeGeneric.mg.18a5a5fae295c5a6
EmsisoftTrojan.Ransom.Amnesia.C (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bmdfw
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.21BE4CB
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Amnesia.C
AhnLab-V3Trojan/Win32.CryptXXX.R208829
Acronissuspicious
McAfeeArtemis!18A5A5FAE295
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Kitoles
PandaTrj/CI.A
TrendMicro-HouseCallMal_Purge
YandexTrojan.GenAsa!naaCZ9xMLiA
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Amnesia.HwsBy6cA

How to remove UDS:Trojan-Ransom.Win32.Purga?

UDS:Trojan-Ransom.Win32.Purga removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment