Ransom

Generic.Ransom.DCRTR.9BBE7C15 removal instruction

Malware Removal

The Generic.Ransom.DCRTR.9BBE7C15 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.DCRTR.9BBE7C15 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.DCRTR.9BBE7C15?


File Info:

crc32: A62A6192
md5: 9d212b348c3ac16d0a1872a61f0b719c
name: 9D212B348C3AC16D0A1872A61F0B719C.mlw
sha1: f5619064f2d8aebfdba0fc3f566cb60f599f9f6e
sha256: 229bd30b5410ba29b6451a0e733481e82ae5bb38fb03ef2453daf6886b0eec54
sha512: 7ea82897d7ba362d881bca7aa5e78c8693dd62d0dfbb9279b9ac40632202df993d1c7f5b41583c7ac910a1e1af149b7b0e83f6dbcab6d776c216f0f4aa2504ac
ssdeep: 384:AZfUr5UIzJ7gMSE2dE0pKQ1qMatslMrMZVIZKjXeeeawcXy4:oV3hdE0pKxMaCnDI6X7NXXy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.DCRTR.9BBE7C15 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005462ba1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.27435
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.Paradise
CylanceUnsafe
ZillyaTrojan.Generic.Win32.518558
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 005462ba1 )
Cybereasonmalicious.48c3ac
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Paradise.B
APEXMalicious
AvastWin32:Filecoder-BK [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.DCRTR.9BBE7C15
NANO-AntivirusTrojan.Win32.Filecoder.fmiamh
ViRobotTrojan.Win32.Ransom.29696.B
MicroWorld-eScanGeneric.Ransom.DCRTR.9BBE7C15
TencentWin32.Trojan.Filecoder.Hufh
Ad-AwareGeneric.Ransom.DCRTR.9BBE7C15
SophosMal/Generic-S
ComodoMalware@#ofutnddd3jhz
BitDefenderThetaAI:Packer.D40E63AA1F
TrendMicroRansom.Win32.PARADISE.SMDS
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.9d212b348c3ac16d
EmsisoftGeneric.Ransom.DCRTR.9BBE7C15 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cyycb
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2A62627
MicrosoftRansom:Win32/Filecoder.BD!MTB
ArcabitGeneric.Ransom.DCRTR.9BBE7C15
GDataGeneric.Ransom.DCRTR.9BBE7C15
TACHYONRansom/W32.Paradise.29696
AhnLab-V3Trojan/Win32.ParadiseRansom.R261572
Acronissuspicious
McAfeeRansomware-GWZ!9D212B348C3A
MAXmalware (ai score=100)
VBA32BScope.Trojan.Fuery
MalwarebytesMalware.AI.3259440198
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.PARADISE.SMDS
RisingRansom.Outsider!1.D74B (CLASSIC)
YandexTrojan.Agent!iMzPAJS0RQE
IkarusTrojan-Ransom.Paradise
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Paradise.EDC4!tr.ransom
AVGWin32:Filecoder-BK [Trj]
Paloaltogeneric.ml

How to remove Generic.Ransom.DCRTR.9BBE7C15?

Generic.Ransom.DCRTR.9BBE7C15 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment