Ransom

Should I remove “Generic.Ransom.Xorist.D4758959”?

Malware Removal

The Generic.Ransom.Xorist.D4758959 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Xorist.D4758959 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • CAPE detected the Xorist malware family
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Binary compilation timestomping detected

How to determine Generic.Ransom.Xorist.D4758959?


File Info:

name: CA982F7F6C170FD6BBBD.mlw
path: /opt/CAPEv2/storage/binaries/3d874a9f0b28ce0dae53e8ef2a1f6677ea30001d52ae4e5d7b9b430733f4ed13
crc32: 07ED5F0B
md5: ca982f7f6c170fd6bbbd0aae127e9e2a
sha1: b5c389d6c6df45e4995e23714ac92bde9c579fac
sha256: 3d874a9f0b28ce0dae53e8ef2a1f6677ea30001d52ae4e5d7b9b430733f4ed13
sha512: 1683df88151ca8916032527984373c7491365aa1af97b3134ec7c57acaa93d6c2a477cd7d806a4befecdfff43336b087ab496363f8ae4ef07fcb42b678812c44
ssdeep: 49152:ETaHalduDKvwG2rR3VkvqbL26UOj9E50pDeKODZDjlUi/v5O+hrr:+mSdCG2rMqP2Ga50ulBH9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T177B523A8E36C68E2CB00517B58596F9993E00FC79AD88CF1F4527049BE7F47F80A265C
sha3_384: 012ad698813926bf86a8b51f5e4764bc2513334ad270f52115cfb447ee27eea9acfaa6047c40ae98ae241eb7127feab3
ep_bytes: 84cef6c7e984fb4389f00fbbd800e10f
timestamp: 2085-05-10 15:55:48

Version Info:

0: [No Data]

Generic.Ransom.Xorist.D4758959 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Ransom.Xorist.D4758959
FireEyeGeneric.mg.ca982f7f6c170fd6
McAfeeArtemis!CA982F7F6C17
CylanceUnsafe
VIPRETrojan-Spy.Win32.Usteal.a (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f52b1 )
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWTrojan ( 0040f52b1 )
Cybereasonmalicious.f6c170
CyrenW32/Usteal.A.gen!Eldorado
SymantecRansom.CryptoTorLocker
ESET-NOD32a variant of Win32/Spy.Usteal.C
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderDeepScan:Generic.Ransom.Xorist.D4758959
NANO-AntivirusTrojan.Win32.Usteal.eriozk
AvastWin32:Trojan-gen
TencentWin32.Trojan.Spnr.Taou
Ad-AwareDeepScan:Generic.Ransom.Xorist.D4758959
SophosML/PE-A + Mal/RufTar-C
ComodoMalCrypt.Indus!@1qrzi1
DrWebDLOADER.Trojan
ZillyaTrojan.Ruftar.Win32.6230
TrendMicroTrojanSpy.Win32.USTEAL.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftDeepScan:Generic.Ransom.Xorist.D4758959 (B)
IkarusVirus.Win32.Heur
GDataDeepScan:Generic.Ransom.Xorist.D4758959
JiangminTrojan.Generic.dwzjr
eGambitGeneric.Malware
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.1054904
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftRansom:Win32/Sorikrypt.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ruftar.R16029
Acronissuspicious
BitDefenderThetaAI:Packer.B51123AF1E
ALYacDeepScan:Generic.Ransom.Xorist.D4758959
VBA32BScope.TrojanPSW.UFR
MalwarebytesMalware.AI.2314299282
TrendMicro-HouseCallTrojanSpy.Win32.USTEAL.SMTH
RisingRansom.Sorikrypt!8.8822 (TFE:2:zWdDOMJvoDE)
YandexTrojanSpy.Usteal!PMIhoqJHOuA
SentinelOneStatic AI – Malicious PE
MaxSecurePSW.Ruftar.htm
FortinetW32/Kryptik.AXP!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Ransom.Xorist.D4758959?

Generic.Ransom.Xorist.D4758959 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment