Ransom Trojan

GenPack:Trojan.Ransom.BFT (B) removal guide

Malware Removal

The GenPack:Trojan.Ransom.BFT (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Trojan.Ransom.BFT (B) virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine GenPack:Trojan.Ransom.BFT (B)?


File Info:

crc32: 6C9CEAAA
md5: 7f357a5213330893712f566cec6f1522
name: 7F357A5213330893712F566CEC6F1522.mlw
sha1: 7f53aaec7e61900a6a66efe5da4001daa8779c46
sha256: aca6ee4e394eb1f2e14842e8f2b132e12884e4a4504a1cc9dcc60168c7d6c64e
sha512: 2a50b34b5cb73c7a2c89745794c45e8bf0c233cad6ff57b23c185a1c15c713ce09c726058119fef2d01990ba118d1e8264f894eab5b5a87f24a0087433dae9ea
ssdeep: 3072:vwtIqPxbumSssbaFbgjB/hsqRGKBPebS5POBc7iHGQxv3lScDYSrBc1DEPBULkzq:vqISumTymqhsQGqeScD7SPSUDEZNzq
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: lpq.exe
FileVersion: 5.1.2600.0 (xpclient.010817-1148)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 5.1.2600.0
FileDescription: TCP/IP Lpq Command
OriginalFilename: lpq.exe
Translation: 0x0409 0x04b0

GenPack:Trojan.Ransom.BFT (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.14977
CynetMalicious (score: 99)
ALYacGenPack:Trojan.Ransom.BFT
CylanceUnsafe
ZillyaTrojan.Ransom.Win32.947
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Ransomware.d587d57c
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.213330
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Petya-6960742-0
KasperskyVHO:Trojan.Win32.Agent.gen
BitDefenderGenPack:Trojan.Ransom.BFT
NANO-AntivirusTrojan.Win32.Encoder.ezlazc
MicroWorld-eScanGenPack:Trojan.Ransom.BFT
TencentWin32.Trojan.Generic.Ajlt
Ad-AwareGenPack:Trojan.Ransom.BFT
SophosMal/Generic-S
ComodoTrojWare.Win32.Ransom.Petya.D@6mmj4l
BitDefenderThetaGen:NN.ZexaF.34758.lmuaaujzbMli
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.7f357a5213330893
EmsisoftGenPack:Trojan.Ransom.BFT (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Petr.e
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1D15836
MicrosoftTrojan:Win32/Occamy.C
ArcabitGenPack:Trojan.Ransom.BFT
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGenPack:Trojan.Ransom.BFT
AhnLab-V3Trojan/Win32.Agent.R215450
McAfeeArtemis!7F357A521333
MAXmalware (ai score=98)
VBA32Trojan.MBRlock
PandaTrj/CI.A
RisingRansom.Petya-Decoder!1.B3CB (CLASSIC)
YandexTrojan.GenAsa!1nshlDZtFpI
IkarusVirus.Win32.Virut.ak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove GenPack:Trojan.Ransom.BFT (B)?

GenPack:Trojan.Ransom.BFT (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment