Ransom

Generic.Ransom.Exmas.F7F1D6B8 malicious file

Malware Removal

The Generic.Ransom.Exmas.F7F1D6B8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Exmas.F7F1D6B8 virus can do?

  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Appends a known encryptJJS ransomware file extension to files that have been encrypted
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
onion1.host
a.tomx.xyz

How to determine Generic.Ransom.Exmas.F7F1D6B8?


File Info:

crc32: EC028DFE
md5: a614aebc74a9f568ef133f5027a8cca1
name: A614AEBC74A9F568EF133F5027A8CCA1.mlw
sha1: c205567c6e4545c293fa677f07ff5828d3c75220
sha256: b0f2ee3844e7efe70a305fcd27c0b0aa5ebc8115d7049bb7058c8d96871e4b2b
sha512: 069a38d0eacd75f8a7562e930af9b0e2cd768015492d52e7514e8d9bdefbd5a5e49c573228fd0c3ff62bfe9774179d541cdf7d507349939a4575e0e602968634
ssdeep: 768:4SFMqQ+aSQSJ7G7uLhp+uOvbeFCc3sb17WL6wSDYBp4GonEF8w9JsGm:PFMqRaSQSJBXHA1C6Z24GRH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Exmas.F7F1D6B8 also known as:

K7AntiVirusTrojan ( 0051f60b1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.MerryXMas
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0051f60b1 )
Cybereasonmalicious.c74a9f
SymantecRansom.BTCware
ESET-NOD32a variant of Generik.HUKDRCM
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGeneric.Ransom.Exmas.F7F1D6B8
NANO-AntivirusTrojan.Win32.Crypted.evfpcu
MicroWorld-eScanGeneric.Ransom.Exmas.F7F1D6B8
TencentWin32.Trojan.Crypt.Lkdg
Ad-AwareGeneric.Ransom.Exmas.F7F1D6B8
SophosMal/Generic-S
ComodoMalware@#1a7gbnr254085
BitDefenderThetaAI:Packer.C62B268816
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_EXMAS.M
McAfee-GW-EditionBehavesLike.Win32.Upatre.ph
FireEyeGeneric.mg.a614aebc74a9f568
EmsisoftGeneric.Ransom.Exmas.F7F1D6B8 (B)
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitGeneric.Ransom.Exmas.F7F1D6B8
AegisLabTrojan.Win32.Generic.4!c
GDataGeneric.Ransom.Exmas.F7F1D6B8
AhnLab-V3Malware/Win32.Ransom_exmas.C2370409
McAfeeArtemis!A614AEBC74A9
MAXmalware (ai score=98)
VBA32suspected of Trojan.Notifier.gen
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_EXMAS.M
RisingTrojan.Generic@ML.98 (RDML:HGQoTmpY18JzKwM4ATXkMw)
YandexTrojan.Agent!OGvB15dkDIo
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetGenerik.HUKDRCM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Exmas.F7F1D6B8?

Generic.Ransom.Exmas.F7F1D6B8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment