Ransom

Ransom.NetWalker.Generic (file analysis)

Malware Removal

The Ransom.NetWalker.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.NetWalker.Generic virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

Related domains:

edgedl.me.gvt1.com

How to determine Ransom.NetWalker.Generic?


File Info:

crc32: 9DE120B1
md5: 2a3dd8079a741452644f09c40d79fd60
name: 2A3DD8079A741452644F09C40D79FD60.mlw
sha1: aef9251a62a8d7cb430f0788d8cf302b8a705419
sha256: 2bce87481a923867aa260cd8fb6c728297a90439fcdd39a2d6b3c027374d1079
sha512: d75a89e664ad67c69aba7782e4d793c5e12f62840ac6889f50abd38db4b55eb6318b9401b6f5af79211cf714cfb292e276c2af13d7ad789d9269572b4abbbb43
ssdeep: 768:3zKn7ztROVQUCO8WQP2Lxxt35B2FCpL6FPnEm7aoHBWM6IR:Wn7vzURNXxbL2h1n75HBWM6I
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom.NetWalker.Generic also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005637c21 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31232
CynetMalicious (score: 100)
CAT-QuickHealRansom.Netwalker
McAfeeArtemis!2A3DD8079A74
CylanceUnsafe
SangforRansom.Win32.NetWalker.S!MTB
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/NetWalker.1f4c721e
K7GWTrojan ( 005637c21 )
Cybereasonmalicious.79a741
SymantecRansom.Cryptolocker
ESET-NOD32a variant of Win32/Filecoder.NetWalker.D
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.DelShad.cwr
BitDefenderGen:Variant.Razy.631035
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Razy.631035
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Razy.631035
SophosMal/Generic-S
ComodoMalware@#2inrgcmsddwl0
BitDefenderThetaGen:NN.ZexaF.34692.hmJfaiN6rso
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Filecoder.R002C0DEV21
McAfee-GW-EditionBehavesLike.Win32.Dropper.cz
FireEyeGeneric.mg.2a3dd8079a741452
EmsisoftGen:Variant.Razy.631035 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3018131
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Filecoder.DD!MTB
ArcabitTrojan.Razy.D9A0FB
AegisLabTrojan.Win32.DelShad.4!c
GDataGen:Variant.Razy.631035
AhnLab-V3Trojan/Win32.Agent.C4064104
VBA32BScope.TrojanPSW.Spy
MAXmalware (ai score=100)
MalwarebytesRansom.NetWalker.Generic
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Filecoder.R002C0DEV21
RisingRansom.NetWalker!1.CFC6 (CLASSIC)
YandexTrojan.Filecoder!XPlvp5MP3DM
IkarusTrojan-Ransom.NetWalker
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/NetWalker.B!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom.NetWalker.Generic?

Ransom.NetWalker.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment