Ransom

What is “Ransom:Win32/Genasom.ER”?

Malware Removal

The Ransom:Win32/Genasom.ER is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.ER virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

edgedl.me.gvt1.com

How to determine Ransom:Win32/Genasom.ER?


File Info:

crc32: 19E68A06
md5: 2462990d2d4cc50304452fd56d4dd071
name: 2462990D2D4CC50304452FD56D4DD071.mlw
sha1: 23d1c79d189103aec040332b24c92e5e361c2da6
sha256: 4968fbd7fcf0d8abc0b59eb16c240d9e78cb05cef93e755ce7f07119e9f996db
sha512: 3bbb356d3bce289a926e5709bb3ba0af0eb76583da6357ee99bb8c4cfd8f5bedc1f411827a4b857a453c4b9f3ae18b7d64eb8efaeffbf70b7afb9a18c5a5f02f
ssdeep: 6144:0NoqTURPoYfMUYiD1ITr0aHl8hliDNkB0ZKrrDXJlByzPTfDa6nWev3WObXBD3f:0N3UR0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Navajo Arturo Pythagoras Kruger Byron
InternalName: ztsdp
FileVersion: 3.01.0009
CompanyName: Semite Gabriel Cheddar Finland
Comments: Moen Claire
ProductName: Nostrand Wilkes
ProductVersion: 3.01.0009
FileDescription: Storey Hawkins
OriginalFilename: ztsdp.exe

Ransom:Win32/Genasom.ER also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00246cc31 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.12370
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.15016
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.35218
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Androm.074cbde6
K7GWTrojan ( 00246cc31 )
Cybereasonmalicious.d2d4cc
CyrenW32/VBInject.1!Generic
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AGM
APEXMalicious
AvastWin32:Cambot-O [Trj]
KasperskyBackdoor.Win32.Androm.jviz
BitDefenderGen:Variant.Symmi.15016
NANO-AntivirusTrojan.Win32.Winlock.edbymc
MicroWorld-eScanGen:Variant.Symmi.15016
TencentWin32.Backdoor.Androm.Hpru
Ad-AwareGen:Variant.Symmi.15016
SophosML/PE-A + Mal/VBCheMan-C
ComodoTrojWare.Win32.Agent.~kst@3yda0g
BitDefenderThetaAI:Packer.62B4F1EA20
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionPWS-Zbot.gen.bbp
FireEyeGeneric.mg.2462990d2d4cc503
EmsisoftGen:Variant.Symmi.15016 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.aaejl
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.18D9E7A
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftRansom:Win32/Genasom.ER
AegisLabTrojan.Win32.Androm.m!c
GDataGen:Variant.Symmi.15016
AhnLab-V3Trojan/Win32.VBKrypt.C88263
McAfeePWS-Zbot.gen.bbp
MAXmalware (ai score=100)
VBA32BScope.Trojan.Jorik
PandaTrj/GdSda.A
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.GenAsa!l/Ye4hNZMA4
IkarusTrojan-Ransom.Timer
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.EEQS!tr
AVGWin32:Cambot-O [Trj]
Paloaltogeneric.ml

How to remove Ransom:Win32/Genasom.ER?

Ransom:Win32/Genasom.ER removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment