Ransom

What is “Ransom:Win32/Genasom!bit”?

Malware Removal

The Ransom:Win32/Genasom!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom!bit virus can do?

  • Attempts to delete volume shadow copies
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Genasom!bit?


File Info:

crc32: 26241DF7
md5: bbacd7e5e7be9de0181e418de9c26c5a
name: BBACD7E5E7BE9DE0181E418DE9C26C5A.mlw
sha1: a0f7bc91937330bdec9bf32bcddc8dd2ab293ff1
sha256: 67697dcd8493f287a880cff6165b903bfe1daf3b55814e90de879cd1fb8df004
sha512: 69ef754c19a749c62f97fd7290c8faf07a7168485a55ca3be1ff12c60c18d39799700026145430783fb91dc0922f2e7eb13adc5c33ab022228dd4a1655a32fc8
ssdeep: 12288:1A8ex8TIEC8Jci+sYGNYCmrgBGKa+tIfzNf6mM7CacKVHm:GXx8TNJcLsYGNYCmrg2+IhS5cKV
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Genasom!bit also known as:

LionicTrojan.Win32.Cryptor.4!c
DrWebTrojan.Encoder.25725
CAT-QuickHealTrojan.Sigmal.S3206508
ALYacTrojan.Ransom.Armage
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.125134
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cryptor.a6700608
K7GWTrojan ( 0001140e1 )
K7AntiVirusTrojan ( 0001140e1 )
CyrenW32/Cryptor.XODF-8161
SymantecRansom.Cryptolocker
ESET-NOD32Win32/Filecoder.NRL
ZonerTrojan.Win32.71205
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Cryptor.btx
BitDefenderTrojan.GenericKD.31115680
NANO-AntivirusTrojan.Win32.Cryptor.ffqxui
MicroWorld-eScanTrojan.GenericKD.31115680
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKD.31115680
SophosMal/Generic-R + Troj/Ransom-FAO
ComodoMalware@#1lw2574e12u1o
BitDefenderThetaGen:NN.ZexaF.34170.YGW@aG6wEUe
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_ARMAGE.THGBDAH
McAfee-GW-EditionGeneric.azp
FireEyeTrojan.GenericKD.31115680
EmsisoftTrojan.Ransom.Armage (A)
JiangminTrojan.Cryptor.hs
WebrootW32.Trojan.GenKD
AviraTR/Genasom.bimth
Antiy-AVLTrojan/Generic.ASMalwS.2712D3B
MicrosoftRansom:Win32/Genasom!bit
GDataWin32.Trojan.Agent.S1F743
TACHYONRansom/W32.Cryptor.828928
AhnLab-V3Trojan/Win32.Davidran.C2596698
McAfeeGeneric.azp
MAXmalware (ai score=94)
VBA32TrojanRansom.Cryptor
MalwarebytesRansom.FileCryptor
PandaTrj/WLT.D
TrendMicro-HouseCallRansom_ARMAGE.THGBDAH
YandexTrojan.GenAsa!ETiG9TnWUD4
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Cryptor.BTX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Genasom!bit?

Ransom:Win32/Genasom!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment