Ransom

Ransom:Win32/Genasom.BA!MTB removal

Malware Removal

The Ransom:Win32/Genasom.BA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.BA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Ransom:Win32/Genasom.BA!MTB?


File Info:

crc32: 8C44A49D
md5: 27954148b47f0e82ebb2723472492f94
name: vps.exe
sha1: 979e5f40edc757912bf906b2369bae25dbf137c9
sha256: bde4e8909950b3d421307364ccde16de14e2ffbec1951e2704b5342c500c577c
sha512: 47ba6f5dbf1e8b37dc1e7b48c87a6b6184f4a1984fb8ac510bd035ad3138c3ca415195560e96850a19fb1cfb07b73416c5cdf9bc5f32d306d33000e8e6771107
ssdeep: 12288:e8PYRxhPdaUfUzUx15/hnTvItli5HfteLP271DB:e8khPdxfUzU3nzItieDo
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Genasom.BA!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.42857982
FireEyeGeneric.mg.27954148b47f0e82
McAfeeArtemis!27954148B47F
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005627381 )
BitDefenderTrojan.GenericKD.42857982
K7GWTrojan ( 005627381 )
Cybereasonmalicious.0edc75
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKD.42857982
KasperskyTrojan-Banker.Win32.Danabot.eiu
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan-banker.Danabot.Hryz
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42857982 (B)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hc
Trapminesuspicious.low.ml.score
SophosMal/RyPack-A
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D28DF5FE
ZoneAlarmTrojan-Banker.Win32.Danabot.eiu
MicrosoftRansom:Win32/Genasom.BA!MTB
AhnLab-V3Trojan/Win32.MalPe.R329073
Acronissuspicious
ALYacTrojan.GenericKD.42858400
Ad-AwareTrojan.GenericKD.42857982
PandaTrj/GdSda.A
ESET-NOD32Win32/Spy.Danabot.L
RisingTrojan.Generic@ML.89 (RDML:ipTxy3rpAmtAKR6dhs/gdQ)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_92%
FortinetPossibleThreat.MU
BitDefenderThetaGen:NN.ZexaF.34100.KuW@aeNzUKC
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/Genasom.BA!MTB?

Ransom:Win32/Genasom.BA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment