Categories: Ransom

How to remove “Generic.Ransom.BTCWare.90C41802”?

The Generic.Ransom.BTCWare.90C41802 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.BTCWare.90C41802 virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.BTCWare.90C41802?


File Info:

crc32: 696CE529md5: 8b6b56ffe18e0d43ed1cb4d461712ee8name: 8B6B56FFE18E0D43ED1CB4D461712EE8.mlwsha1: 735c939a00620c5ffa10890483281bea7f59b2f3sha256: d7747b0a07d26dce5012e65018e38a3fecc0cf29d30666e0679f3e977c40cddfsha512: 923ea00a44fccd4e36e51dea16f364c110ae67e3a776731f549f0315a81f3f1d370eedac76e2d8a3f2fb60b3ba0ff1f690304084cf562b4bff62cb9eed644f5cssdeep: 3072:0TdJZCLXaoag4hrA8/pwetadN8+CYooSdRrn:3TerD6N8+dooSvrntype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.BTCWare.90C41802 also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Trojan ( 0050b3cb1 )
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
DrWeb Trojan.Encoder.11958
Cynet Malicious (score: 100)
CAT-QuickHeal Ransom.Betisrypt.S1420801
ALYac Trojan.Ransom.BTCWare
Cylance Unsafe
Zillya Trojan.Filecoder.Win32.6358
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_60% (D)
Alibaba Ransom:Win32/generic.ali2000027
K7GW Trojan ( 0050b3cb1 )
Cybereason malicious.fe18e0
Cyren W32/Ransom.GH.gen!Eldorado
Symantec Ransom.BTCware
ESET-NOD32 a variant of Win32/Filecoder.BTCware.H
APEX Malicious
Avast Win32:RansomX-gen [Ransom]
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Generic.Ransom.BTCWare.90C41802
NANO-Antivirus Trojan.Win32.Encoder.eswflh
MicroWorld-eScan Generic.Ransom.BTCWare.90C41802
Tencent Malware.Win32.Gencirc.11493361
Ad-Aware Generic.Ransom.BTCWare.90C41802
Sophos ML/PE-A + Troj/Btcware-A
Comodo Malware@#qutp45jpydt2
BitDefenderTheta Gen:NN.ZexaF.34170.huW@aqS86mdi
VIPRE Trojan.Win32.Generic!BT
TrendMicro Ransom_BTCWARE.SMAR
McAfee-GW-Edition GenericRXDK-FH!8B6B56FFE18E
FireEye Generic.mg.8b6b56ffe18e0d43
Emsisoft Generic.Ransom.BTCWare.90C41802 (B)
SentinelOne Static AI – Malicious PE
Jiangmin Trojan.Cryptor.cp
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1103387
Antiy-AVL Trojan/Generic.ASMalwS.21E3D2C
Microsoft Ransom:Win32/Betisrypt.D
Arcabit Generic.Ransom.BTCWare.90C41802
GData Win32.Trojan-Ransom.BTCWare.L
TACHYON Ransom/W32.Cryptor.116224.G
AhnLab-V3 Trojan/Win32.Gryphon.C2108754
Acronis suspicious
McAfee GenericRXDK-FH!8B6B56FFE18E
MAX malware (ai score=100)
VBA32 BScope.Backdoor.Caphaw
Malwarebytes Malware.AI.1940805268
Panda Trj/Genetic.gen
TrendMicro-HouseCall Ransom_BTCWARE.SMAR
Rising Trojan.Generic@ML.100 (RDML:JRD9oRKCAKEEnrEKMVxuUg)
Yandex Trojan.GenAsa!WeqdPsXRM50
Ikarus Trojan-Ransom.BTCWare
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/BTCWare.I!tr.ransom
AVG Win32:RansomX-gen [Ransom]
Paloalto generic.ml

How to remove Generic.Ransom.BTCWare.90C41802?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Should I remove “Malware.AI.3914590665”?

The Malware.AI.3914590665 is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Trojan:Win32/Startpage.YT removal instruction

The Trojan:Win32/Startpage.YT is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

Win32/Injector.Autoit.FXP removal guide

The Win32/Injector.Autoit.FXP is considered dangerous by lots of security experts. When this infection is active,…

46 mins ago

Should I remove “Trojan.Agent.Delf.RVB”?

The Trojan.Agent.Delf.RVB is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

IL:Trojan.MSILZilla.124965 malicious file

The IL:Trojan.MSILZilla.124965 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan.Generic.35601204 removal

The Trojan.Generic.35601204 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago