Ransom

Ransom:Win32/Genasom.DK information

Malware Removal

The Ransom:Win32/Genasom.DK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.DK virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Genasom.DK?


File Info:

crc32: D78C0149
md5: 3bc73fa34bc8b2c084874b7424413cd1
name: 3BC73FA34BC8B2C084874B7424413CD1.mlw
sha1: 24b3e59f286367c54689f3b94e6ae2383803439e
sha256: 51bb8038c65d3ecfa5bf5c11c5bbd9eb84633104308170f2638e8d513ecff0cc
sha512: 6a29b69d74e1d4ce762d5c061b24903d1cabc225443d20a11d234a38ea0e31335d7e05b196ebd520bd87c9ce5a99c608633b5651150af45a5372563c9967457f
ssdeep: 6144:TkVcB5YK+DWO4qhlSt9pTdN9f8FNXT/D4Wt9BZSduD5wpvSl4:wV8YK+DWOjmeH/Dxadkw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Genasom.DK also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00235b871 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.3256
CynetMalicious (score: 100)
ALYacGen:Trojan.ShellStartup.yGW@aCg3nVj
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.531
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Genasom.4279ada1
K7GWTrojan ( 00235b871 )
Cybereasonmalicious.34bc8b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.AFT
APEXMalicious
TotalDefenseWin32/Ransom.GJB
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.ShellStartup.yGW@aCg3nVj
NANO-AntivirusTrojan.Win32.Gimemo.czrvc
MicroWorld-eScanGen:Trojan.ShellStartup.yGW@aCg3nVj
TencentWin32.Trojan.Gimemo.Lnop
Ad-AwareGen:Trojan.ShellStartup.yGW@aCg3nVj
SophosMal/Generic-S
BitDefenderThetaAI:Packer.219B17F421
VIPRETrojan.Win32.Generic!BT
TrendMicroRANSOM_CRYPGENASOM_FE180033.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.3bc73fa34bc8b2c0
EmsisoftGen:Trojan.ShellStartup.yGW@aCg3nVj (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Genasom.wvan
eGambitGeneric.Malware
MicrosoftRansom:Win32/Genasom.DK
ArcabitTrojan.ShellStartup.EA237A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Trojan.ShellStartup.yGW@aCg3nVj
AhnLab-V3Trojan/Win32.Gimemo.C1959779
McAfeeGenericR-HJM!3BC73FA34BC8
MAXmalware (ai score=97)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.4210996535
PandaTrj/CI.A
TrendMicro-HouseCallRANSOM_CRYPGENASOM_FE180033.UVPM
RisingMalware.Undefined!8.C (TFE:5:orfjx2pYkqJ)
YandexTrojan.GenAsa!MWir3f/D3aI
IkarusTrojan.Win32.Ransom
FortinetW32/Generic.AC.271017!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Genasom.HgIASOcA

How to remove Ransom:Win32/Genasom.DK?

Ransom:Win32/Genasom.DK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment