Ransom

Generic.Ransom.Xorist.392BD585 (file analysis)

Malware Removal

The Generic.Ransom.Xorist.392BD585 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Xorist.392BD585 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Generic.Ransom.Xorist.392BD585?


File Info:

crc32: 504C081C
md5: 4bc47294a5d7f790900cedb1abba6688
name: 4BC47294A5D7F790900CEDB1ABBA6688.mlw
sha1: 833ee01e0190a9e719d8ec4d67796bd36c4c413a
sha256: 592b79997bcf90f34659af497ca305e2339422fbdde10988feaf4abc8edde321
sha512: 3325f8e465c11371a486edc0a68a1a972f8faf6c33181a6f0d0b83e60dbe96f2a8ba95080ede8eaa82070e264a44a9804b1cfbee2bc66beb7fe9f6a1533908f8
ssdeep: 49152:7sINvYk7Da5PSowkzsINvYk7Da5PSowk:JYaa5PvhYaa5Pv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Xorist.392BD585 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005451b81 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.94
CynetMalicious (score: 100)
CAT-QuickHealRansom.Genasom.FO4
ALYacTrojan.Ransom.Xorist
CylanceUnsafe
ZillyaTrojan.Xorist.Win32.1589
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Xorist.675fc2af
K7GWTrojan ( 001f8f911 )
Cybereasonmalicious.4a5d7f
BaiduWin32.Trojan.Filecoder.g
CyrenW32/Filecoder.Y.gen!Eldorado
SymantecRansom.CryptoTorLocker
ESET-NOD32a variant of Win32/Filecoder.Q
APEXMalicious
TotalDefenseWin32/Ransom.A!generic
AvastWin32:Filecoder-M [Trj]
ClamAVWin.Trojan.CryptoTorLocker2015-1
KasperskyTrojan-Ransom.Win32.Xorist.gf
BitDefenderGeneric.Ransom.Xorist.392BD585
NANO-AntivirusTrojan.Win32.Xorist.rhtgz
ViRobotTrojan.Win32.A.Xorist.504320
MicroWorld-eScanGeneric.Ransom.Xorist.392BD585
TencentTrojan.Win32.CryptoTorLocker2015.a
Ad-AwareGeneric.Ransom.Xorist.392BD585
SophosMal/Generic-R + Troj/Ransom-EY
ComodoTrojWare.Win32.Kryptik.ER@4o1ar2
BitDefenderThetaGen:NN.ZexaF.34628.XrW@a4kdj6ni
VIPRETrojan.Win32.Ransom.fo (v)
TrendMicroRansom_XORIST.SMA
McAfee-GW-EditionBehavesLike.Win32.VirRansom.tc
FireEyeGeneric.mg.4bc47294a5d7f790
EmsisoftGeneric.Ransom.Xorist.392BD585 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.xupo
WebrootW32.Trojan.CryptoTorLocker2015-
AviraHEUR/AGEN.1114186
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Sorikrypt.A
ArcabitGeneric.Ransom.Xorist.392BD585
AegisLabTrojan.Win32.Xorist.4!c
GDataGeneric.Ransom.Xorist.392BD585
AhnLab-V3Trojan/Win32.Xorist.C633380
Acronissuspicious
McAfeeGenericRXGV-DA!4BC47294A5D7
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.Xorist
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_XORIST.SMA
RisingRansom.Sorikrypt!8.8822 (TFE:dGZlOgKZNz2A8B+pfQ)
YandexTrojan.GenAsa!hRfFrp4f5Io
IkarusTrojan.Win32.Filecoder
FortinetW32/Xorist.DD8C!tr.ransom
AVGWin32:Filecoder-M [Trj]
Qihoo-360Win32/Ransom.Xorist.HxQBEpsA

How to remove Generic.Ransom.Xorist.392BD585?

Generic.Ransom.Xorist.392BD585 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment