Ransom Trojan

Trojan-Ransom.Win32.Gen.geo removal tips

Malware Removal

The Trojan-Ransom.Win32.Gen.geo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Gen.geo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Gen.geo?


File Info:

crc32: D7D09AB0
md5: 856a1db8f60bf59c415d10fe26b1a6c8
name: 856A1DB8F60BF59C415D10FE26B1A6C8.mlw
sha1: ed5043fcd659c320ef8b44a7f937e6968bd96a4a
sha256: 3fd0f916a6068f3c374a13e0eaad2155c5472ac1fe39c253d919909390b7346f
sha512: 4d1cb20e0ac679059a4af581b50b35c6ea8d2aef483c1d4b65566b1293b700740ff418de83e6078b76c399c891998f450d5d96e5151152fa4e8171f9ae8d1ee5
ssdeep: 3072:H63HNSQfMMiv1knZ96KsOfclbSDfz3BgdEV/s8e4wu2rT2pNeZB0b7nx0RGs7Gg:GNfodC6KsAclODtgdW/Zw0t
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Gen.geo also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Generic.j!c
DrWebTrojan.MulDrop7.53115
CynetMalicious (score: 100)
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Satancrypt.daf662ca
K7GWRiskware ( 0040eff71 )
SymantecRansom.CryptXXX
ESET-NOD32a variant of Win32/Filecoder.NOD
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.geo
NANO-AntivirusTrojan.Win32.DelFile.evxbrv
TencentWin32.Trojan.Gen.Dztq
SophosMal/Generic-S
ComodoMalware@#1jkhjmxtaymex
BitDefenderThetaGen:NN.ZexaF.34170.omWaaKmySFpO
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.856a1db8f60bf59c
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gen.pl
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASMalwS.2312447
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win32.Gen
McAfeeArtemis!856A1DB8F60B
MAXmalware (ai score=97)
VBA32BScope.TrojanRansom.Gen
PandaTrj/GdSda.A
YandexTrojan.Gen!G+x4Vksx/G0
IkarusTrojan.Agent
FortinetW32/Gen.GEO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Gen.geo?

Trojan-Ransom.Win32.Gen.geo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment