Ransom

Ransom:Win32/Genasom.BR removal tips

Malware Removal

The Ransom:Win32/Genasom.BR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.BR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Genasom.BR?


File Info:

crc32: D1A4D6F6
md5: f67f422b61d39b3fdcd122beb1f4ffa6
name: F67F422B61D39B3FDCD122BEB1F4FFA6.mlw
sha1: 365b2b85edd8cafe3f6262d504429a4b39f2338a
sha256: 4e372fe55ae36c71fa0dd1304ce4f59e457fd2411e867bd366979135eafddbf2
sha512: d953d33a5dae20234ea64b1a32fa008332ced6b05347f50de63c53a1d5dc5372239fa89c5f50f158ef57dd9da867a36591f010d86a9278ddfe90ee27ee384ada
ssdeep: 1536:l+wp4lScCukbouHFNPF+uJKijX6K8/6BmSPFmtx:l+wp3cVJuB+4K6BJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Genasom.BR also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Fakealert.22141
FireEyeGeneric.mg.f67f422b61d39b3f
ALYacTrojan.Fakealert.22141
CylanceUnsafe
ZillyaTrojan.FakeAV.Win32.325895
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e4091 )
BitDefenderTrojan.Fakealert.22141
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.b61d39
BitDefenderThetaGen:NN.ZexaF.34590.gyW@aO64IZcc
CyrenW32/Bamital.I
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.WX
APEXMalicious
AvastWin32:MalOb-IJ [Cryp]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Genasom.c22b0b7d
NANO-AntivirusTrojan.Win32.PornoBlocker.trnoi
RisingVirus.Ramnit!8.4 (CLOUD)
Ad-AwareTrojan.Fakealert.22141
EmsisoftTrojan.Fakealert.22141 (B)
F-SecureTrojan:W32/Ransomware.A
DrWebTrojan.Winlock.2715
VIPRETrojan.Win32.Bamital.i (v)
TrendMicroTROJ_BAMITAL.SMK
McAfee-GW-EditionW32/Bamital.e
SophosML/PE-A + W32/Ramnit-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/PornoBlocker.abz
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Genasom.BR
ArcabitTrojan.Fakealert.D567D
AhnLab-V3Backdoor/Win32.Shiz.R2353
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Fakealert.22141
CynetMalicious (score: 100)
Acronissuspicious
McAfeeW32/Bamital.e
VBA32Trojan.MTA.01240
MalwarebytesMalware.Heuristic.1006
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_BAMITAL.SMK
TencentWin32.Trojan.Lockscreen.Eddv
YandexTrojan.GenAsa!DLpWdOzx/Fw
IkarusVirus.Win32.Ramnit
eGambitGeneric.Malware
FortinetW32/Drooptroop.SMY!tr
AVGWin32:MalOb-IJ [Cryp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.FakeAv.HgIASOQA

How to remove Ransom:Win32/Genasom.BR?

Ransom:Win32/Genasom.BR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment