Ransom

Ransom:Win32/Enestaller.L!rsm removal tips

Malware Removal

The Ransom:Win32/Enestaller.L!rsm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Enestaller.L!rsm virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ransom:Win32/Enestaller.L!rsm?


File Info:

crc32: 524923C1
md5: edafcb13f06280bef7a21a91d88b868d
name: EDAFCB13F06280BEF7A21A91D88B868D.mlw
sha1: 214d011746de7c7c06e6bbb21f0f3143d141e15c
sha256: dd2c7570aabcd60c3e6262cbafaf89db0510c553511fa5ee12aa86793da4b93d
sha512: d9cf86aeeb920689c5486677c4c08254bedd617a1f3d4e3c2436d619d570bd99fb5b671b0bfdfe9b70e292d89658b1de0b7eb282ec53741884a05a568274f1bf
ssdeep: 3072:9w4gnScG4DI2dcfbyj3QRRb+/QsMAYMjT2TbVl2RsUvo0Nh:992EKARV+/QYT2PusUvJNh
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Ransom:Win32/Enestaller.L!rsm also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.4479269
FireEyeGeneric.mg.edafcb13f06280be
Qihoo-360HEUR/QVM42.2.9B8F.Malware.Gen
McAfeeArtemis!EDAFCB13F062
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 00506d421 )
BitDefenderTrojan.GenericKD.4479269
K7GWTrojan ( 00506d421 )
Cybereasonmalicious.3f0628
SymantecRansom.Cerber!g14
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.DLTT.elzznw
RisingTrojan.Generic@ML.100 (RDML:vH0uSQQIMDjuiey2xTQwpg)
Ad-AwareTrojan.GenericKD.4479269
EmsisoftTrojan.GenericKD.4479269 (B)
ComodoMalware@#pwq07c59seh7
F-SecureTrojan.TR/Dropper.gqwwb
DrWebTrojan.Boaxxe.484
TrendMicroMal_Cerber-NS3b
McAfee-GW-EditionBehavesLike.Win32.Vopak.cc
SophosMal/Generic-R + Mal/Cerber-Z
IkarusTrojan-Ransom.Gryphon
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1116903
MAXmalware (ai score=87)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Enestaller.L!rsm
ArcabitTrojan.Generic.D445925
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Trojan-Ransom.Win32.Agent.gen
GDataTrojan.GenericKD.4479269
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZedlaF.34804.eq4@aGTNBUl
ALYacTrojan.GenericKD.4479269
VBA32BScope.Trojan.Nisloder
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.DLTT
TrendMicro-HouseCallMal_Cerber-NS3b
TencentWin32.Trojan.Generic.Anzr
YandexTrojan.Injector!xsNyoZ3BtN8
SentinelOneStatic AI – Malicious PE – Adware
FortinetW32/Injector.DLWT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Ransom:Win32/Enestaller.L!rsm?

Ransom:Win32/Enestaller.L!rsm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment