Ransom

How to remove “Generic.Ransom.Purge.546D1F37”?

Malware Removal

The Generic.Ransom.Purge.546D1F37 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Purge.546D1F37 virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Modifies boot configuration settings
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Detects Joe or Anubis Sandboxes through the presence of a file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Appends a known Globe ransomware file extension to files that have been encrypted
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Purge.546D1F37?


File Info:

crc32: C6F3B546
md5: dd6cc91b4137e2837ddfc93210cfccaa
name: DD6CC91B4137E2837DDFC93210CFCCAA.mlw
sha1: be31666788fc9f962e22b42029b6db01e11f0b8e
sha256: 6fbf675a47606fc616f667e93179c4d6768ad6a79251bd6a996a91d00d5e2da0
sha512: 1a0a1bf3e9f0a843ad25f823e11b0a9ac4f2c5642abb4cbfc91e4bbc28ed5725aea108bd683caf66ea9650ef7aa1bc06d69b45579b0c6567d165edef3fc8b31d
ssdeep: 3072:q3qvHxwzrXnSK2fjrDyNCY0vQMBqyyETHViYTa8avVM:2eHgNu3yNyQMQyyEDJmM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Purge.546D1F37 also known as:

K7AntiVirusTrojan ( 0050d6e11 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.6182
CynetMalicious (score: 100)
CAT-QuickHealRansom.Genasom.A8
ALYacGeneric.Ransom.Purge.546D1F37
CylanceUnsafe
ZillyaTrojan.Purga.Win32.40
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Purga.905eef9d
K7GWTrojan ( 0050d6e11 )
Cybereasonmalicious.b4137e
SymantecRansom.Purge
ESET-NOD32a variant of Win32/Filecoder.FS
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Malware.Nestha_0000-5633172-0
KasperskyTrojan-Ransom.Win32.Purga.af
BitDefenderGeneric.Ransom.Purge.546D1F37
NANO-AntivirusTrojan.Win32.CryptXXX.ekfbku
MicroWorld-eScanGeneric.Ransom.Purge.546D1F37
TencentWin32.Trojan.Purga.Wtno
Ad-AwareGeneric.Ransom.Purge.546D1F37
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1121085
BitDefenderThetaAI:Packer.78B47C6217
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_PURGE.F117AC
McAfee-GW-EditionGenericRXAW-EI!F31DE6E4943C
FireEyeGeneric.mg.dd6cc91b4137e283
EmsisoftGeneric.Ransom.Purge.546D1F37 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.CryptXXX.zw
AviraHEUR/AGEN.1121085
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.1DD388C
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Contentocrypt.A
ZoneAlarmTrojan-Ransom.Win32.Purga.af
GDataGeneric.Ransom.Purge.546D1F37
TACHYONRansom/W32.DP-Purga.446976
AhnLab-V3Trojan/Win32.Purga.R208330
McAfeeArtemis!DD6CC91B4137
MAXmalware (ai score=87)
VBA32BScope.TrojanRansom.Purga
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_PURGE.F117AC
YandexTrojan.GenAsa!xhGFD5aMDzU
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FS!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove Generic.Ransom.Purge.546D1F37?

Generic.Ransom.Purge.546D1F37 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment