Ransom

About “Ransom:Win32/Genasom.LI” infection

Malware Removal

The Ransom:Win32/Genasom.LI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom.LI virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Genasom.LI?


File Info:

crc32: 83A91053
md5: 744b6f1b3099d482e10c8561387f4a8b
name: 744B6F1B3099D482E10C8561387F4A8B.mlw
sha1: 8f02bd77c45b257148116a5621c2ae9867814364
sha256: 894d47a857fc4c402cab89c23272955a07571d2bc9b29f3390bee2c9387eab65
sha512: 1767e86e658457dae04243446497b34c5e413a28c3f8f06e1ced2cda813d6ca14e8d19d5e60d98df90b3474eaca0c794c5c486e8984c99fc277f96e99cb5bed4
ssdeep: 384:b77VUEDNWdgjBsJpM9t7NQhQPD0v7h69k2XXf/EDHGb0nul5X1mP+fXNoQ/Lyt:8CtJQhpvNQX3EDmAn0XmANT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Genasom.LI also known as:

K7AntiVirusRiskware ( 0040eff71 )
CynetMalicious (score: 99)
CAT-QuickHealRansom.Wiper.S4622209
ALYacTrojan.DistTrack.A
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.530
SangforTrojan.Win32.GenericKD.4
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Genasom.2ea89020
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b3099d
CyrenW32/Agent.XH.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/KillFiles.NJH
APEXMalicious
AvastFileRepMalware
ClamAVWin.Tool.Delete-6775052-0
KasperskyTrojan-Ransom.Win32.Encoder.ayd
BitDefenderTrojan.GenericKD.40836452
NANO-AntivirusTrojan.Win32.Encoder.fldkdb
MicroWorld-eScanTrojan.GenericKD.40836452
TencentMalware.Win32.Gencirc.114d78c6
Ad-AwareTrojan.GenericKD.40836452
SophosMal/Generic-S + Troj/Ransom-FDM
ComodoMalware@#8bewqhv5wv80
BitDefenderThetaGen:NN.ZexaE.34722.cuW@aqCfU7ii
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric Trojan.gs
FireEyeTrojan.GenericKD.40836452
EmsisoftTrojan.GenericKD.40836452 (B)
JiangminTrojan.Wiper.a
AviraTR/Genasom.exevy
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.29D4860
MicrosoftRansom:Win32/Genasom.LI
ArcabitTrojan.Generic.D26F1D64
GDataTrojan.GenericKD.40836452
AhnLab-V3Malware/Gen.Generic.C2893572
McAfeeGeneric Trojan.gs
VBA32BScope.TrojanRansom.Encoder
MalwarebytesTrojan.Deleter
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.86 (RDML:MaTmSIVQhZoup/TrTytmhQ)
YandexTrojan.Wiper!ybi7aM7x+3w
IkarusTrojan-Ransom.Rokku
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KillFiles.NJH!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom:Win32/Genasom.LI?

Ransom:Win32/Genasom.LI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment