Ransom

Win32:Ransom-ZO [Trj] removal guide

Malware Removal

The Win32:Ransom-ZO [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Ransom-ZO [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (El Salvador)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:Ransom-ZO [Trj]?


File Info:

name: 36B68713B9BCA27F26CD.mlw
path: /opt/CAPEv2/storage/binaries/5b0c5fa9d59e440ac231f497e37fc43cd1b34a9c60da103b29be4cd245f9506a
crc32: 7BE30CE9
md5: 36b68713b9bca27f26cd3e6af3a650d0
sha1: dde6a3a9fbff6cdf81d12ab95714c872d910a3ba
sha256: 5b0c5fa9d59e440ac231f497e37fc43cd1b34a9c60da103b29be4cd245f9506a
sha512: f1f5537b969c266ed3910b704bf949032ec2973a46eda7372aaa4159d2608624fd768e89ea8a0b69f1a72666d1f11447cd1319aef5fd68e87a372b242ce48c35
ssdeep: 3072:hr0GTskqdmb6fo6fb8+9pMCtCHVGXi4fEvezI9WUk0b96Z2dKJXT8:h0GeEP6T8vCtCHV/4fEGzP056Z2UJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE441503DB9B3662F4690E3910FC0B1ED719BA043F178BE7A519797AD66B3C22791348
sha3_384: 8d4538e916a2a64e1818934c79e6017a15e65eb581faa6d5256d9f17ff4c96db89ab60a3624781a14bb70e2b93c5055a
ep_bytes: 558bec83c4dc535633c08945dc8945ec
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: Novell BorderManager
CompanyName: www.novell.com
FileDescription: Novell BorderManager
LegalCopyright: Copyright (c) 2009 novell.com All Rights Reserved
LegalTrademarks: novell.com
ProductName: Novell BorderManager
FileVersion: 6.2.0
ProductVersion: 6.2.0
InternalName: Novell BorderManager
OriginalFilename: bordermanager.exe
ResourcesEditedWith: Restorator 2007 Trial
ResourceEditorWWW: http://www.bome.com/Restorator/
Translation: 0x0409 0x04b0

Win32:Ransom-ZO [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Zygug.6
FireEyeGeneric.mg.36b68713b9bca27f
CAT-QuickHealTrojan.GenericIH.S11740496
ALYacGen:Heur.Zygug.6
MalwarebytesMalware.Heuristic.1001
ZillyaTrojan.Foreign.Win32.2094
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaWorm:Win32/Dorkbot.aee092b8
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.3b9bca
VirITTrojan.Win32.Foreign.UBT
CyrenW32/S-9af908cd!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32Win32/Dorkbot.B
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Dorkbot-8011204-0
BitDefenderGen:Heur.Zygug.6
NANO-AntivirusTrojan.Win32.NgrBot.bfnyom
AvastWin32:Ransom-ZO [Trj]
SophosMal/Generic-S
F-SecureWorm.WORM/Dorkbot.I.427
DrWebBackDoor.IRC.NgrBot.42
VIPREGen:Heur.Zygug.6
TrendMicroTSPY_RANSOM_CA25019E.TOMC
McAfee-GW-EditionW32/Dorkbot!36B68713B9BC
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Zygug.6 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Zygug.6
JiangminTrojan/Foreign.bhc
GoogleDetected
AviraWORM/Dorkbot.I.427
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Foreign
XcitiumMalware@#252pl5papyk7b
ArcabitTrojan.Zygug.6
ViRobotTrojan.Win32.A.Foreign.192512.B
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/DorkBot.DU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.R47515
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.36196.qG0@a0FcoFlG
VBA32BScope.Malware-Cryptor.Oop
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTSPY_RANSOM_CA25019E.TOMC
TencentWin32.Trojan.Generic.Gajl
YandexTrojan.GenAsa!E3+PXwRutxc
IkarusGen:Heur
FortinetW32/Injector.YWU!tr
AVGWin32:Ransom-ZO [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:Ransom-ZO [Trj]?

Win32:Ransom-ZO [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment