Ransom

About “Ransom:Win32/Genasom.CT” infection

Malware Removal

The Ransom:Win32/Genasom.CT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.CT virus can do?

  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r8—sn-bpb5oxu-3c2r.gvt1.com
update.googleapis.com

How to determine Ransom:Win32/Genasom.CT?


File Info:

crc32: 71CD7C2F
md5: 2fba223fed8f75fbb4179a2fb45a5113
name: 2FBA223FED8F75FBB4179A2FB45A5113.mlw
sha1: c5eac5d098a98e78ea177565492a6ecdef04bb96
sha256: 9854edbbd32e800c0a6010d631d8cd06bb956b6a1b682b9758aafe6c8b01a2b2
sha512: cbca4879e050c12f18fbbd421350948c5927fa929db8c32c86c6a6938f8c31ef16ce392732977c6ad8b9063cc7850816b3faec697d74b1778d19e8f8e2b25e44
ssdeep: 1536:dUXtEjtC4v1H6OjrBu1mjkLVJkdKkEdv8r5sjVV:IWf9Hlj9u8jkLEodv8r5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Genasom.CT also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e4091 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.65359
CynetMalicious (score: 100)
CAT-QuickHealTrojanDropper.Wlock.AA6
ALYacGen:Variant.Ser.Mikey.2065
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.1853
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/HmBlocker.cd6794c5
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.fed8f7
SymantecTrojan.Ransomlock.F
ESET-NOD32a variant of Win32/LockScreen.AEW
APEXMalicious
AvastWin32:LockScreen-DE [Trj]
KasperskyTrojan-Ransom.Win32.HmBlocker.cqb
BitDefenderGen:Variant.Ser.Mikey.2065
NANO-AntivirusTrojan.Win32.HmBlocker.ihgww
ViRobotTrojan.Win32.A.HmBlocker.99840
MicroWorld-eScanGen:Variant.Ser.Mikey.2065
TencentMalware.Win32.Gencirc.10b88df2
Ad-AwareGen:Variant.Ser.Mikey.2065
SophosMal/Generic-S
ComodoTrojWare.Win32.Trojan.Ransom.~J@465pje
BitDefenderThetaAI:Packer.6E19A0151F
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.2fba223fed8f75fb
EmsisoftGen:Variant.Ser.Mikey.2065 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/HmBlocker.acp
AviraTR/Fraud.Gen2
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.8F03B8
MicrosoftRansom:Win32/Genasom.CT
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ser.Mikey.2065
AhnLab-V3Trojan/Win32.HmBlocker.C128537
Acronissuspicious
McAfeeGenericR-HFG!2FBA223FED8F
MAXmalware (ai score=100)
VBA32BScope.Trojan.MulDrop
MalwarebytesMalware.AI.4118367162
PandaTrj/CI.A
RisingTrojan.Win32.Winlock.a (CLASSIC)
YandexTrojan.GenAsa!PvFNmOPROus
IkarusTrojan-Ransom.HmBlocker
MaxSecureTrojan.Malware.1896097.susgen
FortinetW32/LockScreen.AFA!tr
AVGWin32:LockScreen-DE [Trj]
Paloaltogeneric.ml

How to remove Ransom:Win32/Genasom.CT?

Ransom:Win32/Genasom.CT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment