Ransom

What is “Generic.Ransom.Qwerty.F78760BE”?

Malware Removal

The Generic.Ransom.Qwerty.F78760BE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Qwerty.F78760BE virus can do?

  • A process attempted to delay the analysis task.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.Qwerty.F78760BE?


File Info:

crc32: 33C084AC
md5: bc0f5be2973072b60f3ebcb934d52704
name: BC0F5BE2973072B60F3EBCB934D52704.mlw
sha1: 47c28842617e524351dfb9d490b7e02be4cedbfa
sha256: 31189756d0a94e3ae69ee25dd5b1dd54f32f45ca2a6c667e471286ea202e4c6e
sha512: 64502451bb9d95a73d66d244c9ab338d0282ec29b77487565f1a13bf22fddf32978129bb95411223e39a2dfc928c77211c042709e139bf8475c34eb92fd90372
ssdeep: 12288:Kp5+/p5z+n7DWjFPp86CXwXzH50vrqo3D0hmIODNRH0:a5+/pRKQbCXCiv7IBODNRH0
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Qwerty.F78760BE also known as:

K7AntiVirusTrojan ( 005297ad1 )
LionicTrojan.Win32.Generic.j!c
DrWebTrojan.Siggen7.41118
CAT-QuickHealMalware.Sigmal.S2290302
ALYacGeneric.Ransom.Qwerty.F78760BE
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7204
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 005297ad1 )
Cybereasonmalicious.297307
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NPQ
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.hoj
BitDefenderGeneric.Ransom.Qwerty.F78760BE
NANO-AntivirusTrojan.Win32.RansomHeur.eyxxou
MicroWorld-eScanGeneric.Ransom.Qwerty.F78760BE
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.Qwerty.F78760BE
SophosTroj/Dycler-C
ComodoMalware@#18g5un2c1w38f
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-GKF!BC0F5BE29730
FireEyeGeneric.Ransom.Qwerty.F78760BE
EmsisoftTrojan.FileCoder (A)
JiangminTrojan.Gen.bjm
Antiy-AVLTrojan/Generic.ASMalwS.250134A
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Kasitoo.A!rsm
GDataWin32.Trojan-Ransom.GPGQwerty.A
AhnLab-V3Malware/Win32.Generic.C2421214
McAfeeRansomware-GKF!BC0F5BE29730
MAXmalware (ai score=100)
VBA32TrojanRansom.Gen
PandaTrj/GdSda.A
RisingRansom.Kasitoo!1.B144 (CLASSIC)
YandexTrojan.GenAsa!ycLJBf1jhug
IkarusTrojan.Injector
FortinetW32/Dycler.C!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Qwerty.F78760BE?

Generic.Ransom.Qwerty.F78760BE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment