Ransom

About “Generic.Ransom.BitcoinX2.C04688C7” infection

Malware Removal

The Generic.Ransom.BitcoinX2.C04688C7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.BitcoinX2.C04688C7 virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Generic.Ransom.BitcoinX2.C04688C7?


File Info:

crc32: EE0FF718
md5: 3b2871300bfbf6625b1418cab8f9fc63
name: 3B2871300BFBF6625B1418CAB8F9FC63.mlw
sha1: 4175ab618877b4f8550efc03f3ba3c11cabffaa6
sha256: d783cf538391adf7c046171fd5c241bee9ee3d03b3a809cef5f199b3817577f4
sha512: b48be27fee568e9b9217464b4e7d393a7173ffd973aba5535fc0cb4737eb88029bb8e4974e9186ec2bdd47a9d3df0bfdcd13d5c3044b798cf4bf20cfde84a81e
ssdeep: 6144:7enUxNDsjRH/clfU6vKKz+F2Jurv+HE4KpH1cl4a1yyhLohZRfU6vhm:7en+Dg2C2KUu2ZE3pVcl4Oto3+2h
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: BB
FileVersion: 5.01.0001
CompanyName: P
ProductName: Bit
ProductVersion: 5.01.0001
OriginalFilename: BB.exe

Generic.Ransom.BitcoinX2.C04688C7 also known as:

K7AntiVirusP2PWorm ( 0052362d1 )
LionicTrojan.Win32.Generic.4!c
CAT-QuickHealWorm.Vb.S1950167
ALYacGeneric.Ransom.BitcoinX2.C04688C7
K7GWP2PWorm ( 0052362d1 )
Cybereasonmalicious.00bfbf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VB.OTF
APEXMalicious
AvastWin32:Malware-gen
KasperskyEmail-Worm.Win32.VB.vxa
BitDefenderGeneric.Ransom.BitcoinX2.C04688C7
NANO-AntivirusTrojan.Win32.VB.ewusyh
MicroWorld-eScanGeneric.Ransom.BitcoinX2.C04688C7
TencentWin32.Worm-email.Vb.Ljue
Ad-AwareGeneric.Ransom.BitcoinX2.C04688C7
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34170.Em0@ae0!kMhi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VBObfus.gh
FireEyeGeneric.mg.3b2871300bfbf662
EmsisoftGeneric.Ransom.BitcoinX2.C04688C7 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1122147
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGeneric.Ransom.BitcoinX2.C04688C7
McAfeeGenericRXDS-XI!3B2871300BFB
MAXmalware (ai score=94)
VBA32BScope.Worm.VB
MalwarebytesMalware.AI.4039039365
PandaTrj/GdSda.A
IkarusWorm.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.OTF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.BitcoinX2.C04688C7?

Generic.Ransom.BitcoinX2.C04688C7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment