Ransom

About “Dropped:Generic.Ransom.PhiladephiaB.C9D6993E” infection

Malware Removal

The Dropped:Generic.Ransom.PhiladephiaB.C9D6993E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Ransom.PhiladephiaB.C9D6993E virus can do?

  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Dropped:Generic.Ransom.PhiladephiaB.C9D6993E?


File Info:

crc32: 6E3D3C75
md5: 416747a611de5b31e4d82ed76c1fa04e
name: 416747A611DE5B31E4D82ED76C1FA04E.mlw
sha1: c7cef6950785a60f30bdb7a44fb0737cd3a29839
sha256: 2b86581595e4c46c65341d8f05233a0b4dc4fde123e6791d8121c8ae7d3551ac
sha512: 4649775fe5677f62b669ca947af2af473420ecb20e952c9a63a45a1efa673c37b0082767251cf75b7462c652e0759e1532d9433d30a8f64d8eacccf58b7d3ba2
ssdeep: 12288:FCdOy3vVrKxR5CXbNjAOxK/j2n+4YG/6c1mFFja3mXgcjfRlgsUBgaclWnAFQ:FCdxte/80jYLT3U1jfsWaK/FQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Dropped:Generic.Ransom.PhiladephiaB.C9D6993E also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!e
DrWebTrojan.Siggen7.10497
CynetMalicious (score: 99)
CAT-QuickHealTrojan.AutoIt.Dropper.ZZ
ALYacDropped:Generic.Ransom.PhiladephiaB.C9D6993E
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.611de5
SymantecRansom.Philadelphia
ESET-NOD32Win32/Filecoder.Philadelphia.E
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Philadelphia-7057772-0
KasperskyTrojan-Ransom.Win32.Agent.iza
BitDefenderDropped:Generic.Ransom.PhiladephiaB.C9D6993E
NANO-AntivirusTrojan.Win32.Filecoder.fcdqjo
MicroWorld-eScanDropped:Generic.Ransom.PhiladephiaB.C9D6993E
TencentWin32.Trojan.Agent.Palr
Ad-AwareDropped:Generic.Ransom.PhiladephiaB.C9D6993E
SophosMal/Generic-S + Troj/PhilRns-A
ComodoMalware@#3bi6qveh3ebpm
BitDefenderThetaAI:Packer.F5FF277D17
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_STAMPADO.SMAUIT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.ch
FireEyeDropped:Generic.Ransom.PhiladephiaB.C9D6993E
EmsisoftDropped:Generic.Ransom.PhiladephiaB.C9D6993E (B)
AviraHEUR/AGEN.1100102
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataDropped:Generic.Ransom.PhiladephiaB.C9D6993E
AhnLab-V3Trojan/Win32.Agent.C2560086
McAfeeArtemis!416747A611DE
MAXmalware (ai score=99)
MalwarebytesRansom.Philadelphia
PandaTrj/CI.A
TrendMicro-HouseCallRansom_STAMPADO.SMAUIT
RisingRansom.Agent/Autoit!1.B5E9 (CLASSIC)
IkarusWorm.Win32.Filecoder
FortinetAutoIt/Philadelphia.E!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Dropped:Generic.Ransom.PhiladephiaB.C9D6993E?

Dropped:Generic.Ransom.PhiladephiaB.C9D6993E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment