Ransom

What is “Ransom:Win32/Genasom.AR!MTB”?

Malware Removal

The Ransom:Win32/Genasom.AR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.AR!MTB virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Genasom.AR!MTB?


File Info:

crc32: 80BE07B7
md5: 7df850b43f3f28a67b8160c4265bc726
name: 7DF850B43F3F28A67B8160C4265BC726.mlw
sha1: 522377eced5e1694d36e45da75037d87e84b3729
sha256: 56b483bc7bf3708d49c6d326dc36e3b350aa431028ea05e7f1e7fd63177fb19c
sha512: c6bb2271a794da8a7b5ac6f7e634f1d4173dbaa54fbc778dd29651fc99a5096b974f3bdd0c28775392760f8253bdb55ff7303a33915525ccd0d6a4f52d526225
ssdeep: 6144:VVnlJTOqEq9/qDZHDi1GVbjf9I7gpklv0KH:VV/OqR9/qDZuGVjXpBK
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: edab.exe
FileVersion: 1.0.0.1
CompanyName: MS Edab
ProductName: Edab Service
ProductVersion: 1.0.0.1
FileDescription: Edab Service
OriginalFilename: edab.exe
Translation: 0x0409 0x04b0

Ransom:Win32/Genasom.AR!MTB also known as:

K7AntiVirusTrojan ( 005693621 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.32028
CAT-QuickHealTrojan.GenericRI.S14353567
ALYacTrojan.Ransom.Outsider
CylanceUnsafe
SangforRansom.Win32.Genasom.AR!MTB
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Schoolboy.324fc489
K7GWTrojan ( 005693621 )
Cybereasonmalicious.43f3f2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Outsider.H
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Schoolboy.gen
BitDefenderGen:Trojan.AV-Killer.mu0@aKuOY0ai
NANO-AntivirusTrojan.Win32.Schoolboy.hmldkc
MicroWorld-eScanGen:Trojan.AV-Killer.mu0@aKuOY0ai
TencentWin32.Trojan.Filecoder.Angi
Ad-AwareGen:Trojan.AV-Killer.mu0@aKuOY0ai
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34722.mu0@aKuOY0ai
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.OUTSIDER.THFBBBO
McAfee-GW-EditionGenericRXNK-AG!7DF850B43F3F
FireEyeGen:Trojan.AV-Killer.mu0@aKuOY0ai
EmsisoftGen:Trojan.AV-Killer.mu0@aKuOY0ai (B)
JiangminTrojan.Generic.forwr
AviraHEUR/AGEN.1116537
Antiy-AVLTrojan/Generic.ASMalwS.309E553
MicrosoftRansom:Win32/Genasom.AR!MTB
ArcabitTrojan.AV-Killer.E485F8
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Trojan.AV-Killer.mu0@aKuOY0ai
AhnLab-V3Malware/Win32.Generic.C3680047
McAfeeGenericRXNK-AG!7DF850B43F3F
MAXmalware (ai score=100)
VBA32BScope.Adware.Foxiebro
MalwarebytesRansom.Outsider
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.OUTSIDER.THFBBBO
YandexTrojan.Filecoder!lLVsneRdeNI
IkarusTrojan-Ransom.Outsider
MaxSecureTrojan.Malware.425.susgen
FortinetW32/Cryptor.CZK!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Genasom.AR!MTB?

Ransom:Win32/Genasom.AR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment