Ransom

Generic.Ransom.CloudSword.D764162D removal guide

Malware Removal

The Generic.Ransom.CloudSword.D764162D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.CloudSword.D764162D virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Generic.Ransom.CloudSword.D764162D?


File Info:

name: D5AA75BB393355756257.mlw
path: /opt/CAPEv2/storage/binaries/41920913663df199683fb9f2970f4da7d73048ee8d639cc79939a20930b49910
crc32: E2F476A8
md5: d5aa75bb3933557562574ca8b3257000
sha1: 51e83d28e858eb9a72b6d1970e9fd5ddde9f0306
sha256: 41920913663df199683fb9f2970f4da7d73048ee8d639cc79939a20930b49910
sha512: 528af36f82714922560aa601209ef5946e02a17f3fb8e0342ec272818c4fe5596bf2fb2f8af5f27833290fa3d446e3636a4d23b9624eaa90aa2cec50a4ecfddc
ssdeep: 6144:1wW4/Ub0SOrVKa0hbdUCeyJHsLe10yT8SPsPMfVoE1v49ZsNPsFuwLmpIGpSgKG+:eUoSOrVKa0hbdUC708JoFcaFuH+ij2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15EA4E3CC74ECAC91C00846F02735D1EDE1F46F011DAAEA01BABE3E919355B95AF66B0D
sha3_384: ba9fe478f7723f03eac04f052345ed452c4c2207a7bf482442976fd16f7a7df3ec6424fc9c17465b88f624b52b2af13d
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Generic.Ransom.CloudSword.D764162D also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Ransom.CloudSword.D764162D
FireEyeDeepScan:Generic.Ransom.CloudSword.D764162D
McAfeeArtemis!D5AA75BB3933
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusTrojan ( 0058deb21 )
BitDefenderDeepScan:Generic.Ransom.CloudSword.D764162D
K7GWTrojan ( 0058deb21 )
Cybereasonmalicious.b39335
CyrenW32/Injector.ATY.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.ERBG
TrendMicro-HouseCallTROJ_FRS.0NA103B422
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.aoawa
AlibabaRansom:Application/ObfusInjector.1e137644
RisingTrojan.Injector!8.C4 (CLOUD)
SophosMal/Generic-S + Troj/Steal-CHS
DrWebTrojan.Inject4.25227
TrendMicroTROJ_FRS.0NA103B422
McAfee-GW-EditionNSIS/ObfusInjector.h
SentinelOneStatic AI – Suspicious PE
EmsisoftDeepScan:Generic.Ransom.CloudSword.D764162D (B)
APEXMalicious
WebrootW32.Injector.Gen
AviraTR/Injector.czpyf
MAXmalware (ai score=89)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Woreflint.A!cl
ZoneAlarmTrojan.Win32.Inject.aoawa
GDataMSIL.Trojan-Spy.SnakeKeylogger.8C33UI
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.CloudSword.D764162D
MalwarebytesTrojan.Injector
YandexTrojan.Igent.bXpRwu.35
IkarusTrojan.Win32.Injector
FortinetW32/Injector.ERAJ!tr
AVGWin32:SpywareX-gen [Trj]
AvastWin32:SpywareX-gen [Trj]

How to remove Generic.Ransom.CloudSword.D764162D?

Generic.Ransom.CloudSword.D764162D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment