Ransom

Generic.Ransom.Enigma.9BBD503B (file analysis)

Malware Removal

The Generic.Ransom.Enigma.9BBD503B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Enigma.9BBD503B virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.Enigma.9BBD503B?


File Info:

crc32: 6D931973
md5: d679d43e5a0d885244ec570f77dde065
name: D679D43E5A0D885244EC570F77DDE065.mlw
sha1: 1e4fc669bf45728e87ad9a4e11266760f2be048c
sha256: fc71c64e019742b8c63a6592a892269720694c623e69ec932ab4a95018bbbc92
sha512: 55200dacf0c3e7bec3a733064cc27707522b9f0636fe5e51c8c2f083519003312f085eee21f7fd244611dd3f713180d38e95829b82989f376298a5b9f230722a
ssdeep: 6144:07UOKy0qK8X1eSa/6/QW4QS3JMfQk0slW:kUO4H8XkSa/6/uSYTslW
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Enigma.9BBD503B also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Crynigma.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5384
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Dynamer.S17976
ALYacDeepScan:Generic.Ransom.Enigma.9BBD503B
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Enigma.44682a41
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.e5a0d8
CyrenW32/S-d9895c18!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Enigma.F
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Buho-7564755-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Enigma.9BBD503B
NANO-AntivirusTrojan.Win32.Encoder.efmblc
MicroWorld-eScanDeepScan:Generic.Ransom.Enigma.9BBD503B
TencentWin32.Trojan.Crynigma.Wrgj
Ad-AwareDeepScan:Generic.Ransom.Enigma.9BBD503B
SophosMal/Generic-S
ComodoMalware@#190gu1v2uw6ho
F-SecureHeuristic.HEUR/AGEN.1126848
BitDefenderThetaGen:NN.ZexaF.34110.puW@a4aqcQni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.d679d43e5a0d8852
EmsisoftDeepScan:Generic.Ransom.Enigma.9BBD503B (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Crynigma.j
AviraHEUR/AGEN.1126848
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Ransom]/Win32.Crynigma
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Aicat.A!ml
ArcabitDeepScan:Generic.Ransom.Enigma.9BBD503B
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Ransom.Enigma.9BBD503B
AhnLab-V3Trojan/Win32.Crynigma.C1521794
McAfeeArtemis!D679D43E5A0D
MAXmalware (ai score=86)
VBA32Hoax.Crynigma
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:IiFNiv4m+XQk2XFWD1G7eQ)
YandexTrojan.GenAsa!9IcFrHRb5Ok
IkarusTrojan-Ransom.Enigma
FortinetW32/Generic.AP.13E0C!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Enigma.9BBD503B?

Generic.Ransom.Enigma.9BBD503B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment