Ransom

How to remove “Generic.Ransom.SamSam.C593FFC7”?

Malware Removal

The Generic.Ransom.SamSam.C593FFC7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.SamSam.C593FFC7 virus can do?

  • Creates RWX memory
  • Exhibits behavior characteristic of iSpy Keylogger
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.SamSam.C593FFC7?


File Info:

crc32: 087AC7A5
md5: 286d1495a80c126a63c26a5610d515e6
name: 286D1495A80C126A63C26A5610D515E6.mlw
sha1: 3840eff73b8b611df62a10cacd75cae181b710b1
sha256: 0c1504ff73135e2a7920afac1c49c6ed1b11ac120b589fec08a87b05f457ebd2
sha512: fa98d8a2b0deef487392e5dc8eca89867c4aa88b7ec7e8624647884bd26912bebc93adb6d4434695fd51fd31061bed90b2660e6c759069c258d47838f78f387c
ssdeep: 768:50JPSh/E2mqzDjA6M9zAgyT0jxsDRpCTwCp5B:ISRxjAB9zPygjxCpCTwCpf
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: @2017
Assembly Version: 5.2.3.9
InternalName: WinDir.exe
FileVersion: 6.2.3.6
CompanyName: Microsoft
LegalTrademarks: Microsoft
Comments: Desktop Windows Manager
ProductName: Desktop Windows Manager
ProductVersion: 6.2.3.6
FileDescription: Desktop Windows Manager
OriginalFilename: WinDir.exe

Generic.Ransom.SamSam.C593FFC7 also known as:

K7AntiVirusTrojan ( 004ff8a21 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.6671
CynetMalicious (score: 99)
ALYacTrojan.Ransom.SamSam
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.3678
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:MSIL/Samas.5a9e825a
K7GWTrojan ( 004ff8a21 )
Cybereasonmalicious.5a80c1
CyrenW32/Azorult.D.gen!Eldorado
SymantecInfostealer.Limitail
ESET-NOD32a variant of MSIL/Filecoder.Samas.B
APEXMalicious
AvastWin32:Ransom-AYO [Trj]
KasperskyHEUR:Trojan-Ransom.MSIL.Generic
BitDefenderGeneric.Ransom.SamSam.C593FFC7
NANO-AntivirusTrojan.Win32.Encoder.ejewix
ViRobotTrojan.Win32.S.SamSam.52224.A
MicroWorld-eScanGeneric.Ransom.SamSam.C593FFC7
TencentMalware.Win32.Gencirc.10bce9dc
Ad-AwareGeneric.Ransom.SamSam.C593FFC7
SophosMal/Generic-R + Troj/Samas-C
ComodoMalware@#391tvnosf34km
F-SecureHeuristic.HEUR/AGEN.1109348
BitDefenderThetaGen:NN.ZemsilF.34722.dm0@aqBro3b
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_SAMAS.SMI0
McAfee-GW-EditionRansomware-FEF!286D1495A80C
FireEyeGeneric.mg.286d1495a80c126a
EmsisoftGeneric.Ransom.SamSam.C593FFC7 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.qcot
AviraHEUR/AGEN.1109348
Antiy-AVLTrojan/Generic.ASMalwS.1D06D1E
MicrosoftRansom:MSIL/Samas.E
ArcabitGeneric.Ransom.SamSam.C593FFC7
AegisLabTrojan.MSIL.Generic.j!c
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Generic
GDataGeneric.Ransom.SamSam.C593FFC7
AhnLab-V3Trojan/Win32.Samas.C1676066
McAfeeRansomware-FEF!286D1495A80C
MAXmalware (ai score=100)
VBA32Trojan-Ransom.MSIL.Samas
MalwarebytesMalware.AI.2056418218
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_SAMAS.SMI0
YandexTrojan.Encoder!LS+U9HNYJZ4
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/FilecoderSamas.B!tr.ransom
AVGWin32:Ransom-AYO [Trj]
Paloaltogeneric.ml

How to remove Generic.Ransom.SamSam.C593FFC7?

Generic.Ransom.SamSam.C593FFC7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment