Ransom

What is “Ransom:Win32/Genasom.EK”?

Malware Removal

The Ransom:Win32/Genasom.EK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.EK virus can do?

  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Ransom:Win32/Genasom.EK?


File Info:

crc32: 20BFFC2F
md5: 6f1cebddcd7bf967133f1d3f66e370b0
name: 6F1CEBDDCD7BF967133F1D3F66E370B0.mlw
sha1: 01e955b103ab373c2131b8ae1a85e056dec50ff3
sha256: 26c19eb35e0c5f941a6c0f71058230c6a9bf4881406fec99eb22dba8fd44bca3
sha512: 0a09671fc85164d8ecc25bd3d0412f620c98fa9993c79ea8b8fb803065116139b06fcb282f9ac2de72566d50cd7d1492aa69bb1232094c3e6329467f38323f97
ssdeep: 768:HyKqKQx2X7TZrbzq7o1nc7+fpvHR2B1FCh7kmamUD6W1r:SKqKQu7T9bKo1c7+fpvHRW/CFXJU3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Genasom.EK also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jacard.204559
FireEyeGeneric.mg.6f1cebddcd7bf967
McAfeeArtemis!6F1CEBDDCD7B
CylanceUnsafe
ZillyaTrojan.SAM.Win32.23
BitDefenderGen:Variant.Jacard.204559
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Ransom.I!generic
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Ransom-8827
KasperskyTrojan-Ransom.Win32.SAM.ac
AlibabaRansom:Win32/Genasom.2c465ff6
NANO-AntivirusTrojan.Win32.SAM.felmk
ViRobotTrojan.Win32.A.SAM.37376
AegisLabTrojan.Win32.SAM.j!c
TencentWin32.Trojan.Sam.Wpts
Ad-AwareGen:Variant.Jacard.204559
TACHYONTrojan/W32.DP-Small.37376.F
SophosMal/Generic-S
ComodoMalware@#3abduhxsrs86d
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Siggen2.64420
VIPREBehavesLike.Win32.Malware.wlk (mx-v)
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Jacard.204559 (B)
JiangminTrojan/Sam.h
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Ransom]/Win32.SAM
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Genasom.EK
ArcabitTrojan.Jacard.D31F0F
ZoneAlarmTrojan-Ransom.Win32.SAM.ac
GDataGen:Variant.Jacard.204559
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.HmBlocker.R10671
BitDefenderThetaGen:NN.ZelphiCO.34608.cGW@a0Gv6!e
ALYacGen:Variant.Jacard.204559
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Winlock.gen
MalwarebytesMachineLearning/Anomalous.95%
PandaGeneric Malware
ZonerTrojan.Win32.33975
ESET-NOD32a variant of Win32/LockScreen.AIB
RisingRansom.SAM!8.6C5F (CLOUD)
YandexTrojan.LockScreen!RpJljE+x/zc
IkarusTrojan-Ransom.Gimemo
FortinetW32/SAM.AC!tr
WebrootW32.Malware.Gen
AVGWin32:Trojan-gen
Qihoo-360Win32/RootKit.Rootkit.7e5

How to remove Ransom:Win32/Genasom.EK?

Ransom:Win32/Genasom.EK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment