Ransom

How to remove “Generic.Ransom.Koolova.94D35C84”?

Malware Removal

The Generic.Ransom.Koolova.94D35C84 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Koolova.94D35C84 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.Koolova.94D35C84?


File Info:

crc32: 97A0A18A
md5: 9abd72ce629b106a7debd260ac5e2fce
name: 9ABD72CE629B106A7DEBD260AC5E2FCE.mlw
sha1: d012dd66935a2dbee97b05f72ac1dc33c9748c62
sha256: 36894e8ca6127d4844dc9f1ee13cf30eec50a79ad982f7e2c24834d69aeee526
sha512: 72097c23944436b1c5b478f58b65d754009cf0e6aecd4fe79862997b0ede27832d95e5e639e1d1acda8fedef568774ca0fd37fdb1c2764e7414712709224d1f8
ssdeep: 1536:1jiumbluVcVZ8HnGLviE0YER1sIXbBx0ki2tSwmH:1KlmcanGLv9ER1C2IH
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2015
Assembly Version: 1.0.0.0
InternalName: DUMB.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: DUMB
ProductVersion: 1.0.0.0
FileDescription: DUMB
OriginalFilename: DUMB.exe

Generic.Ransom.Koolova.94D35C84 also known as:

K7AntiVirusTrojan ( 0056a4581 )
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.Encoder.15077
CynetMalicious (score: 99)
ALYacGeneric.Ransom.Koolova.94D35C84
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
AlibabaRansom:MSIL/FileCoder.de309efb
K7GWTrojan ( 0056a4581 )
Cybereasonmalicious.e629b1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.AK
APEXMalicious
AvastMSIL:LockScreen-BJ [Trj]
ClamAVWin.Ransomware.Koolova-9850494-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGeneric.Ransom.Koolova.94D35C84
NANO-AntivirusTrojan.Win32.Filecoder.eetvka
MicroWorld-eScanGeneric.Ransom.Koolova.94D35C84
TencentWin32.Trojan.Generic.Hwmv
Ad-AwareGeneric.Ransom.Koolova.94D35C84
SophosMal/Generic-R + Mal/Crypdum-A
ComodoMalware@#19l4twl2th3x5
BitDefenderThetaGen:NN.ZemsilF.34088.em0@aCM0Uzk
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.Ransom.Koolova.94D35C84
EmsisoftGeneric.Ransom.Koolova.94D35C84 (B)
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1133963
MicrosoftRansom:MSIL/FileCoder.PA!MTB
ArcabitGeneric.Ransom.Koolova.94D35C84
GDataMSIL.Trojan-Ransom.Filecoder.AN
AhnLab-V3Trojan/Win32.Occamy.C2499816
McAfeeArtemis!9ABD72CE629B
MAXmalware (ai score=88)
MalwarebytesMalware.AI.622795446
PandaTrj/CryptoWall.C
YandexTrojan.Filecoder!ETWuxDG9oKE
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.DY!tr.ransom
AVGMSIL:LockScreen-BJ [Trj]

How to remove Generic.Ransom.Koolova.94D35C84?

Generic.Ransom.Koolova.94D35C84 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment