Ransom Virus

Virus.Win32.PolyRansom.e removal

Malware Removal

The Virus.Win32.PolyRansom.e is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Win32.PolyRansom.e virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Created a service that was not started
  • Anomalous binary characteristics

How to determine Virus.Win32.PolyRansom.e?


File Info:

name: 0967C024682DC9631C63.mlw
path: /opt/CAPEv2/storage/binaries/ae5f727db3b2942cc5fe339112d6193bd3c6f00f901f38c973ca0cb98caf849b
crc32: E23FF1B6
md5: 0967c024682dc9631c63120659465cd7
sha1: ffba8273d198c1d910e2bc3398867e6cf3d2884d
sha256: ae5f727db3b2942cc5fe339112d6193bd3c6f00f901f38c973ca0cb98caf849b
sha512: 19ce017caa9ba0a39a6cc05dad618d84a0b9b536161d3135ec1c65a4f01f1b39fb96f08434b67898f98dd04da3a2f94e36b7ed4cd98930e9a94f8999c960d377
ssdeep: 6144:TzkhZBQBr+e8vAlKOO7cxLCiWbwi+Uhu6CZgnE9W3b:TzuZBmrQAlMcxLAU6rnEQr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D34225BBB0A2F53E3BD033B681A79DC93D88A3715FED24E764A6981C397D474C28204
sha3_384: 47658620a643a270c9ac75035d453037f6a4d982cd883e32be14151dc1958eed53c4735c4f307b4ef971dc8287e889b4
ep_bytes: 53b820316300bb78563412b978563412
timestamp: 2014-12-24 07:26:24

Version Info:

0: [No Data]

Virus.Win32.PolyRansom.e also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Doboc.Gen.2.Dam
FireEyeGeneric.mg.0967c024682dc963
CAT-QuickHealW32.Tempedreve.A5
ALYacWin32.Doboc.Gen.2.Dam
CylanceUnsafe
ZillyaVirus.PolyRansom.Win32.4
K7AntiVirusVirus ( 005223721 )
K7GWTrojan ( 004b936c1 )
Cybereasonmalicious.4682dc
BaiduWin32.Trojan.Kryptik.ii
CyrenW32/Ransom.BL.gen!Eldorado
SymantecW32.Tempedreve
ESET-NOD32Win32/Spy.Tuscas.K
APEXMalicious
ClamAVWin.Trojan.Agent-1349155
KasperskyVirus.Win32.PolyRansom.e
BitDefenderWin32.Doboc.Gen.2.Dam
NANO-AntivirusTrojan.Win32.PolyRansom.dpzftw
SUPERAntiSpywareTrojan.Agent/Gen-Tempedreve
AvastWin32:Crypt-RYR [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareWin32.Doboc.Gen.2.Dam
TACHYONTrojan/W32.Doboc.B
SophosML/PE-A + Troj/EncPk-AQ
ComodoTrojWare.Win32.Kryptik.CTYE@5ixzst
DrWebTrojan.Siggen13.52726
VIPREWorm.Win32.Tempedreve.a (v)
TrendMicroPE_URSNIF.B-O
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftWin32.Doboc.Gen.2.Dam (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Doboc.Gen.2.Dam
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.272
MicrosoftTrojan:Win32/MultiPlug.DA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Invader.R130516
Acronissuspicious
McAfeeW32/PdfCrypt.b!0967C024682D
MAXmalware (ai score=82)
VBA32TrojanDropper.Daws
MalwarebytesTrojan.Agent.ADA
TrendMicro-HouseCallPE_URSNIF.B-O
RisingTrojan.Spy.Win32.Tuscas.b (CLASSIC)
YandexTrojan.GenAsa!LyJXQNI6Zvo
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.CTYE!tr
BitDefenderThetaAI:FileInfector.52E8454215
AVGWin32:Crypt-RYR [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureVirus.PolyRansom.e

How to remove Virus.Win32.PolyRansom.e?

Virus.Win32.PolyRansom.e removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment