Ransom

Ransom:Win32/Genasom.AM removal instruction

Malware Removal

The Ransom:Win32/Genasom.AM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.AM virus can do?

  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
pornoklik.com
www.hugedomains.com
www.bing.com
ocsp.digicert.com
cdn.jsdelivr.net
static.hugedomains.com
fonts.googleapis.com
use.typekit.net
www.googletagmanager.com
secure.globalsign.com
ocsp.pki.goog
fonts.gstatic.com
www.youtube.com

How to determine Ransom:Win32/Genasom.AM?


File Info:

crc32: 8625F555
md5: 8eebe3306b67072cc80c3e14042231cd
name: 8EEBE3306B67072CC80C3E14042231CD.mlw
sha1: 2fcc918b388835a6e33c44386aa009c0fc56a66d
sha256: 5bb5c0d322ea7733261e16ffd77f62b4775ca6037c56757fa0a3a1d440a80052
sha512: f4e8c99f01863949097292670bf18d5b325e657e39626be0dab6302c70a8b5146be31a85e5596edcd478e0baf790c0781c0b026edd2cc9c507b6f5b61a3fe59e
ssdeep: 768:jG0bqgQiLLA/qkDVulqNkUo9vkkzUzpVCtcN6mO5Oi8Cf6WYP9jqOH7Gt6uR:C+qgQcLA/zMsR2vrzU32j6bqObb6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Genasom.AM also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Lmir.laiL
DrWebTrojan.Winlock.origin
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.12238
CylanceUnsafe
ZillyaTrojan.PornoBlocker.Win32.174
SangforTrojan.Win32.AGEN.1031366
AlibabaRansom:Win32/Genasom.e68db68a
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.06b670
CyrenW32/Trojan.PPRE-7659
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.PI
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Ransom-309
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Fugrafa.12238
NANO-AntivirusTrojan.Win32.MBBlocker.dsugqb
ViRobotSpyware.Ransom.PornoBlocker.59392.B
MicroWorld-eScanGen:Variant.Fugrafa.12238
TencentWin32.Trojan.Pornobrick.Egfb
Ad-AwareGen:Variant.Fugrafa.12238
SophosML/PE-A + Troj/Vilsel-Gen
ComodoSuspicious@#oy7firsazrgc
BitDefenderThetaAI:Packer.183521171F
VIPREBehavesLike.Win32.Malware.wlk (mx-v)
TrendMicroRansom_Genasom.R067C0DGH21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.8eebe3306b67072c
EmsisoftGen:Variant.Fugrafa.12238 (B)
WebrootTrojan:Win32/Ransom.AM
AviraHEUR/AGEN.1123018
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.83A2F
MicrosoftRansom:Win32/Genasom.AM
GDataGen:Variant.Fugrafa.12238
McAfeeArtemis!8EEBE3306B67
MAXmalware (ai score=100)
VBA32BScope.Trojan.Creeper.vb
MalwarebytesMalware.AI.3924704969
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Genasom.R067C0DGH21
YandexTrojan.GenAsa!JenNVYb1y+4
IkarusTrojan-Ransom.PornoBrick
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PornoBlocker.PE!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Ransom.Genasom.HwUBEpsA

How to remove Ransom:Win32/Genasom.AM?

Ransom:Win32/Genasom.AM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment