Ransom

About “Generic.Ransom.Small.BF53F7BE” infection

Malware Removal

The Generic.Ransom.Small.BF53F7BE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Small.BF53F7BE virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the Chaos malware family

How to determine Generic.Ransom.Small.BF53F7BE?


File Info:

name: 48AF16C07990A3AF9FB8.mlw
path: /opt/CAPEv2/storage/binaries/3b026f4e1eb8f8ad47c314da5f7dc368470cb1516aee560ebb9cb99c2194d367
crc32: 01B495D8
md5: 48af16c07990a3af9fb8e529a10e598c
sha1: 9801c43dba35f81b39929ce6e8d978b6f4797e77
sha256: 3b026f4e1eb8f8ad47c314da5f7dc368470cb1516aee560ebb9cb99c2194d367
sha512: 1db4944be63ed9975c4ff2371bba0fbf04e7c8208b30436c9ea6031867a238b9e1fb2c0852ebcba5e4663c21b14d25b681267484044d299a98e6a24be7ed5ed4
ssdeep: 384:atWZPzzxAm1vmEYv082r7OUmgeYfdQPP+lyOy5o91UXgln82vda:f7zxAmmMXrEgeYwlho9xJ82M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147C2B454B7FA4636F6FF9F7869F251014B36B952EC29D74E088D118E0C22B8CC960B67
sha3_384: d9626e6cf46ba644cd0350593983708458921253ebb1a3ea890682923ec8a0a3d4de42ed009d95956680767ce4c72015
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-05-12 13:54:01

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Ran_Final.exe
LegalCopyright:
OriginalFilename: Ran_Final.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Generic.Ransom.Small.BF53F7BE also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGeneric.Ransom.Small.BF53F7BE
CAT-QuickHealTrojan.Generic.TRFH383
ALYacGeneric.Ransom.Small.BF53F7BE
CylanceUnsafe
SangforVirus.Win32.Save.a
Cybereasonmalicious.07990a
CyrenW32/Azorult.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/ClipBanker.MZ
APEXMalicious
ClamAVWin.Ransomware.Hydracrypt-9878672-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGeneric.Ransom.Small.BF53F7BE
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGeneric.Ransom.Small.BF53F7BE
EmsisoftGeneric.Ransom.Small.BF53F7BE (B)
DrWebTrojan.ClipBankerNET.7
VIPREGeneric.Ransom.Small.BF53F7BE
TrendMicroRansom.MSIL.CHAOS.SMJLM
McAfee-GW-EditionGenericRXTC-EM!48AF16C07990
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.48af16c07990a3af
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1250041
MicrosoftRansom:MSIL/Filecoder.PK!MSR
ArcabitGeneric.Ransom.Small.BF53F7BE
GDataGeneric.Ransom.Small.BF53F7BE
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.FTD.C4597900
Acronissuspicious
McAfeeGenericRXTC-EM!48AF16C07990
MAXmalware (ai score=85)
VBA32Ransom.MSIL.Chaos.Heur
MalwarebytesMalware.AI.3944804856
RisingRansom.Destructor!1.B060 (CLASSIC)
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/ClipBanker.SX!tr
BitDefenderThetaGen:NN.ZemsilF.34806.bm0@aCdizUk
AVGWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.Small.BF53F7BE?

Generic.Ransom.Small.BF53F7BE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment