Ransom

About “Mal/Generic-R + Troj/Ransome-XN” infection

Malware Removal

The Mal/Generic-R + Troj/Ransome-XN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Ransome-XN virus can do?

  • Attempts to make use of the Filter Manager
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Troj/Ransome-XN?


File Info:

name: D4407D528D2F76528350.mlw
path: /opt/CAPEv2/storage/binaries/97291605608ef879bea343deb170f6e662acb5cc82f749a3c483c8603053215b
crc32: F95720E3
md5: d4407d528d2f76528350a95e3bac1e3c
sha1: 6bf93c710b8df5949c7ad4bab262411bc9374503
sha256: 97291605608ef879bea343deb170f6e662acb5cc82f749a3c483c8603053215b
sha512: 245f89e5de0e2146e3a1e2aa1fc619cc0a3f3aeaca15ec85032d2113c95f08d5410dd4a07d27ac7e69229b436678b9d7a906c89330592f719a09a9f97cb9266c
ssdeep: 196608:wL/nzmQOBs6Q+BatvPIOqmZbuUjUyYZj/sh+UVL4I+ZFRo:wzzN3wOqmZ6UIxZj/A+ULqZFe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CCB6BE32B6C18071E167027455A9E3395A7B7F704731CAC7A3E4FD9A28713C1AA3AB53
sha3_384: 02932e35de3ef894cbd5d1054946e97fd9ca793c7be9cf804a4a020155c0763da056ab1829abc13bf60ac5e19a4d143a
ep_bytes: e819810000e97ffeffff558bec8b4d10
timestamp: 2014-08-19 22:43:38

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Ransome-XN also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.47365958
FireEyeGeneric.mg.d4407d528d2f7652
ALYacTrojan.GenericKD.47365958
MalwarebytesMalware.Heuristic.1003
SangforBackdoor.Win32.Bladabindi.1
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Ransome.317fda2b
K7GWTrojan ( 004bcce41 )
APEXMalicious
BitDefenderTrojan.GenericKD.47365958
AvastFileRepMetagen [Trj]
Ad-AwareTrojan.GenericKD.47365958
EmsisoftTrojan.GenericKD.47365958 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPRETrojan.GenericKD.47365958
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
SophosMal/Generic-R + Troj/Ransome-XN
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraHEUR/AGEN.1230733
MicrosoftTrojan:Win32/Casdet!rfn
GDataTrojan.GenericKD.47365958
CynetMalicious (score: 100)
McAfeePolyPatch-UPX
CylanceUnsafe
RisingBackdoor.MSIL.Bladabindi!1.9DE6 (CLOUD)
FortinetW32/PolyPatch.UPX!tr
AVGFileRepMetagen [Trj]

How to remove Mal/Generic-R + Troj/Ransome-XN?

Mal/Generic-R + Troj/Ransome-XN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment