Ransom

What is “Ransom:Win32/Enestaller.V!rsm”?

Malware Removal

The Ransom:Win32/Enestaller.V!rsm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Enestaller.V!rsm virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Enestaller.V!rsm?


File Info:

crc32: 7422BB81
md5: ed42d00b6b5b42cf80c69697eae60762
name: ED42D00B6B5B42CF80C69697EAE60762.mlw
sha1: b6d5dcea66a0dff2d79baf7d76d7e583cd79a7c7
sha256: 09bcf3c7dbfa8f5e5e106485d719334ba0f82da9ba9c14fd86307abc2cacd120
sha512: 3398ef51fbc74da279abc25d0600a4d14f08c9a47293a356688e50fd9c13db40cb483b1229c5b94a5f2ca8febece38521a4da6db6d624db59bd728f33f417ec9
ssdeep: 6144:+wHysEX4dxE9YIvSXaS7K1WU0rX60ctQ2+MiyP8T6BDLDHGYvdU736apku:1EXCxAY6S5QWU0b6rtQ2+qS6xDHEl5
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Ransom:Win32/Enestaller.V!rsm also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005097f11 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Cryptolocker.3
CylanceUnsafe
ZillyaTrojan.Generic.Win32.213497
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Enestaller.e4b5bf20
K7GWTrojan ( 005097f11 )
Cybereasonmalicious.b6b5b4
SymantecPacked.NSISPacker!g6
ESET-NOD32a variant of Win32/Injector.DMYP
ZonerTrojan.Win32.55200
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Cryptolocker.3
NANO-AntivirusTrojan.Win32.DMYP.emyltg
MicroWorld-eScanGen:Variant.Ransom.Cryptolocker.3
TencentWin32.Trojan.Inject.Alsc
SophosMal/Generic-S + Mal/Cerber-Z
ComodoMalware@#mus8unxj2tb2
BitDefenderThetaGen:NN.ZedlaF.34790.cu8@aOJj0chi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTLOCKENC.DLFLWJ
McAfee-GW-EditionRDN/Ransom.cg
FireEyeGeneric.mg.ed42d00b6b5b42cf
EmsisoftTrojan-Ransom.Cryptolocker (A)
SentinelOneStatic AI – Suspicious PE
AviraTR/Injector.xdutf
eGambitUnsafe.AI_Score_83%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Enestaller.V!rsm
SUPERAntiSpywareRansom.CryptoLocker/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Cryptolocker.3
McAfeeArtemis!ED42D00B6B5B
MAXmalware (ai score=94)
VBA32TrojanRansom.Enestaller
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYPTLOCKENC.DLFLWJ
RisingTrojan.Win32.Enestaller.k (CLASSIC)
YandexTrojan.Injector!hg0neD0zpoQ
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DMYB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HyoDEpsA

How to remove Ransom:Win32/Enestaller.V!rsm?

Ransom:Win32/Enestaller.V!rsm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment