Categories: Ransom

Generic.Ransom.SamSam.0CF29C95 removal tips

The Generic.Ransom.SamSam.0CF29C95 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.SamSam.0CF29C95 virus can do?

  • Creates RWX memory
  • Exhibits behavior characteristic of iSpy Keylogger
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.SamSam.0CF29C95?


File Info:

crc32: ADA62019md5: fb29a0baaca035cf028ae07f44b0cb79name: FB29A0BAACA035CF028AE07F44B0CB79.mlwsha1: b41b28a82bb493024bb6157d3385c4345365532csha256: 3a6ec7a33dd2c7678d3fe5ccf238cf7420c7a0fed649eee34d26fbfca93de973sha512: cc3dd725d349ffa6f044e6489ceb2bb7e260660f39da2079c5ae38637aef3d1dd7365cfc21d491121a3c7797dda25d0f569a58aebb540711c4e03f9c2c786cdessdeep: 3072:7xa0xaha0xaha0xaha0xafs6othebbsnDgjHOCTwCppU:7xzxczxczxczxYbWktype: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0LegalCopyright: ImprudenceAssembly Version: 5.6.7.7InternalName: reprotin2.exeFileVersion: 2.6.3.5CompanyName: ImprudenceLegalTrademarks: serviceComments: All decisively dispatched instrumentProductName: favourableProductVersion: 2.6.3.5FileDescription: immediate recommend containedOriginalFilename: reprotin2.exe

Generic.Ransom.SamSam.0CF29C95 also known as:

K7AntiVirus Trojan ( 004ff8a31 )
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
DrWeb Trojan.Encoder.12296
Cynet Malicious (score: 99)
CAT-QuickHeal Trojan.MsilFC.S16693359
ALYac Trojan.Ransom.SamSam
Cylance Unsafe
Zillya Trojan.Filecoder.Win32.6040
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_60% (D)
K7GW Trojan ( 004ff8a31 )
Cybereason malicious.aaca03
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Filecoder.Samas.B
APEX Malicious
Avast Win32:Malware-gen
Kaspersky HEUR:Trojan.MSIL.DOTHETUK.gen
BitDefender Generic.Ransom.SamSam.0CF29C95
NANO-Antivirus Trojan.Win32.Encoder.eqpche
MicroWorld-eScan Generic.Ransom.SamSam.0CF29C95
Tencent Win32.Trojan.Samsam.Xybt
Ad-Aware Generic.Ransom.SamSam.0CF29C95
Sophos ML/PE-A + Troj/Samas-D
BitDefenderTheta Gen:NN.ZemsilF.34050.im0@aCeMobf
VIPRE Trojan.Win32.Generic!BT
TrendMicro Mal_Samas-1
McAfee-GW-Edition Trojan-FNAM!FB29A0BAACA0
FireEye Generic.mg.fb29a0baaca035cf
Emsisoft Trojan-Ransom.SamSam (A)
SentinelOne Static AI – Malicious PE
Webroot W32.Malware.Gen
Avira TR/Dropper.Gen2
Antiy-AVL Trojan/Generic.ASMalwS.219C08A
Microsoft Ransom:MSIL/SamSam.D
GData Generic.Ransom.SamSam.0CF29C95
McAfee Trojan-FNAM!FB29A0BAACA0
MAX malware (ai score=100)
Panda Trj/GdSda.A
TrendMicro-HouseCall Mal_Samas-1
Yandex Trojan.Filecoder!QvWAue97Gy0
Ikarus Trojan-Ransom.FileCrypter
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/FilecoderSamas.B!tr.ransom
AVG Win32:Malware-gen
Paloalto generic.ml
Qihoo-360 Win32/Ransom.Generic.HwMAEpsA

How to remove Generic.Ransom.SamSam.0CF29C95?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Virus:Win32/Expiro.L”?

The Virus:Win32/Expiro.L is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

Trojan:MSIL/Formbook.AMBA!MTB removal instruction

The Trojan:MSIL/Formbook.AMBA!MTB is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

Should I remove “Trojan-PSW.Win32.CoinStealer.bh”?

The Trojan-PSW.Win32.CoinStealer.bh is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

WebWatcher.Spyware.Monitor.DDS removal

The WebWatcher.Spyware.Monitor.DDS is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

What is “Lazy.519114”?

The Lazy.519114 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “Malware.AI.3622831725”?

The Malware.AI.3622831725 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago