Ransom

What is “Ransom:Win32/Enestaller.J!rsm”?

Malware Removal

The Ransom:Win32/Enestaller.J!rsm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Enestaller.J!rsm virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ransom:Win32/Enestaller.J!rsm?


File Info:

crc32: 5BA95A0F
md5: 4e1903c1b9dfb1801342802a4fade85c
name: 4E1903C1B9DFB1801342802A4FADE85C.mlw
sha1: 9352d5e356ab14e7bf82818709de4076bb3eff93
sha256: 26e4c38d2ec506d30800e88eaf3b259736c0d8b0c63eaf5f75be92dc56274118
sha512: ecf2cc355c9e69e9cca61ecd4ae9f12b70fda958228ccd51a40c6c27e3edbd65dfe82dcb2a9086e9216f1a7a7f8838aa0ff2a561d101fc16498943e790bfd0fb
ssdeep: 6144:EAsBZT0I3r1JWCzO8MOKzr/Z54B36FMNx5oLMjNlAUBiOWfLWNT/kYcXjXUHsqwi:+0I3+CzO1O6r1AL+UB/WUPiXUGeH
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Ransom:Win32/Enestaller.J!rsm also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
FireEyeGeneric.mg.4e1903c1b9dfb180
McAfeeRDN/Ransom.cb
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforRansom.Win32.Cerber.J
K7AntiVirusTrojan ( 005071721 )
BitDefenderTrojan.Ransom.NSIS.Cerber.A
K7GWTrojan ( 005071721 )
Cybereasonmalicious.1b9dfb
BitDefenderThetaAI:Packer.8312AEAD21
CyrenW32/Cerber.DXJZ-2544
SymantecPacked.NSISPacker!g5
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.adthm
NANO-AntivirusTrojan.Win32.DLWT.elzzak
MicroWorld-eScanTrojan.Ransom.NSIS.Cerber.A
RisingRansom.Enestedel!8.E513 (TFE:5:I7nzNnEzBqC)
Ad-AwareTrojan.Ransom.NSIS.Cerber.A
ComodoMalware@#wcjie4oozpv5
ZillyaTrojan.Inject.Win32.210018
TrendMicroRansom_CRYPTLOCK.DLFLVS
EmsisoftTrojan.Ransom.NSIS.Cerber.A (B)
IkarusTrojan.Win32.Injector
AviraHEUR/AGEN.1116909
KingsoftWin32.Troj.Gener.(kcloud)
MicrosoftRansom:Win32/Enestaller.J!rsm
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AhnLab-V3Malware/Win32.Ransom_crilock.C1825901
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.NSIS.Cerber.A
ESET-NOD32a variant of Win32/Injector.DNKS
VBA32TrojanRansom.Enestedel
ALYacTrojan.Ransom.NSIS.Cerber.A
MAXmalware (ai score=100)
PandaTrj/Ransom.Z
TrendMicro-HouseCallRansom_CRYPTLOCK.DLFLVS
TencentWin32.Trojan.Inject.Pdmn
YandexTrojan.Injector!iDMpV6+StWs
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.DLWT!tr
WebrootW32.Trojan.Dropper
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.Cerber.HyoDzi4A

How to remove Ransom:Win32/Enestaller.J!rsm?

Ransom:Win32/Enestaller.J!rsm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment