Ransom

Should I remove “Dropped:Generic.Ransom.PhiladephiaB.3FF046EC”?

Malware Removal

The Dropped:Generic.Ransom.PhiladephiaB.3FF046EC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Ransom.PhiladephiaB.3FF046EC virus can do?

  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Dropped:Generic.Ransom.PhiladephiaB.3FF046EC?


File Info:

crc32: 9A79DF96
md5: 209d8681b144475c2637b0d94c391dfc
name: 209D8681B144475C2637B0D94C391DFC.mlw
sha1: eb799b0042900921c715b137a8905a867cad03fc
sha256: 68b748ed71bc58a580120b1caef2085f45175c416e8401f04ea3b31804301ff4
sha512: 15ac697595abcd6bceb2db3383e9db82fcce00a2b7a058fd5f217a2eac0b5021cdf976e2ef81a631e13e0f1f5c8898db1141ba7fb9684e3c551a74a2d764a41d
ssdeep: 12288:BozGdX0M4ornOmZIzfMwHHQmRROXKLb2WsqX:B4GHnhIzOaP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

Dropped:Generic.Ransom.PhiladephiaB.3FF046EC also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00502b391 )
DrWebTrojan.Siggen7.10497
CynetMalicious (score: 99)
CAT-QuickHealTrojan.AutoIt.Dropper.ZZ
ALYacDropped:Generic.Ransom.PhiladephiaB.3FF046EC
CylanceUnsafe
ZillyaTrojan.Snocry.Win32.520
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Starter.ali1001008
K7GWTrojan ( 00502b391 )
Cybereasonmalicious.1b1444
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Philadelphia.E
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Philadelphia-7057772-0
KasperskyTrojan-Ransom.Win32.Snocry.ctr
BitDefenderDropped:Generic.Ransom.PhiladephiaB.3FF046EC
NANO-AntivirusTrojan.Win32.Filecoder.eluhnf
MicroWorld-eScanDropped:Generic.Ransom.PhiladephiaB.3FF046EC
TencentWin32.Trojan.Snocry.Hpij
Ad-AwareDropped:Generic.Ransom.PhiladephiaB.3FF046EC
SophosMal/Generic-S + Troj/PhilRns-A
ComodoMalware@#17hhe3h71yte2
BitDefenderThetaAI:Packer.F5FF277D17
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_STAMPADO.F117BO
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.fc
FireEyeGeneric.mg.209d8681b144475c
EmsisoftDropped:Generic.Ransom.PhiladephiaB.3FF046EC (B)
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1102700
MicrosoftRansom:Win32/FileCryptor
GDataDropped:Generic.Ransom.PhiladephiaB.3FF046EC
McAfeeArtemis!209D8681B144
MAXmalware (ai score=88)
VBA32TrojanRansom.Snocry
MalwarebytesMalware.AI.3260077485
PandaTrj/CI.A
TrendMicro-HouseCallRansom_STAMPADO.F117BO
RisingRansom.Agent/Autoit!1.B5E9 (CLASSIC)
IkarusWorm.Win32.Filecoder
FortinetAutoIt/Philadelphia.E!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Dropped:Generic.Ransom.PhiladephiaB.3FF046EC?

Dropped:Generic.Ransom.PhiladephiaB.3FF046EC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment