Categories: Ransom

Generic.Ransom.FileCryptor.DDS removal

The Generic.Ransom.FileCryptor.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.FileCryptor.DDS virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the Nitro malware family
  • Binary compilation timestomping detected

How to determine Generic.Ransom.FileCryptor.DDS?


File Info:

name: E59C087E7D76FC0B4410.mlwpath: /opt/CAPEv2/storage/binaries/0a3fe6221f0c48b938a5509b993891bd7076aa9cca0ed1071b89fba3ac2b6702crc32: 11ED1BE4md5: e59c087e7d76fc0b44101101aacaede1sha1: 816cbc3cab558691150f81cfeed637e712373ce5sha256: 0a3fe6221f0c48b938a5509b993891bd7076aa9cca0ed1071b89fba3ac2b6702sha512: ea6772a21396795eb7132f73dded180f22a510d521a9d5dd1dafc31f654d95a3df854cb166bb2d934769f076ec54b33a065c734786d4fd4cbf6f53b258b54e0fssdeep: 768:QKsMqCXfVcWlQM9ZkiANIUL5YLDwUzc80gmq3oP/oDx:QKseSM9ZkiAPar/0O8/ottype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T1D553542852738A2DC47C82B815FB2F7C27B0AF565460C76D4A78D2AC3F277B68D10B56sha3_384: 604d6febc4a907c88ef82fb422ff82c74d1360d173b0a85ddc874bf4fd76a005209d613ffdc0958b6dd72e58a4a4a4d1ep_bytes: ff250020400000000000000000000000timestamp: 2049-07-01 19:12:39

Version Info:

Translation: 0x0000 0x04b0Comments: CompanyName: FileDescription: NitroRansomwareFileVersion: 1.0.0.0InternalName: NitroRansomware.exeLegalCopyright: Copyright © 2021LegalTrademarks: OriginalFilename: NitroRansomware.exeProductName: NitroRansomwareProductVersion: 1.0.0.0Assembly Version: 1.0.0.0

Generic.Ransom.FileCryptor.DDS also known as:

Bkav W32.AIDetectNet.01
MicroWorld-eScan IL:Trojan.MSILZilla.19713
ClamAV Win.Ransomware.Ransomx-9863383-0
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
ALYac IL:Trojan.MSILZilla.19713
VIPRE IL:Trojan.MSILZilla.19713
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 0057ab121 )
K7GW Trojan ( 0057ab121 )
Cybereason malicious.e7d76f
VirIT Trojan.Win32.Encoder.BYCN
Cyren W32/Nitro.A.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Filecoder.AHT
APEX Malicious
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Ransom.Win32.Generic
BitDefender IL:Trojan.MSILZilla.19713
Avast Win32:RansomX-gen [Ransom]
Tencent Trojan.Win32.Agent.zi
Ad-Aware IL:Trojan.MSILZilla.19713
Emsisoft IL:Trojan.MSILZilla.19713 (B)
DrWeb Trojan.Encoder.33865
TrendMicro Ransom.MSIL.NITRO.SMA
McAfee-GW-Edition Ransom-Nitro!E59C087E7D76
FireEye Generic.mg.e59c087e7d76fc0b
Sophos Troj/Nitro-Gen
Ikarus Gen.Ransom
Avira HEUR/AGEN.1232324
MAX malware (ai score=89)
Microsoft Ransom:MSIL/Nitro.MK!MTB
Arcabit IL:Trojan.MSILZilla.D4D01
GData MSIL.Trojan-Stealer.AnarchyGrabber.C
Google Detected
AhnLab-V3 Ransomware/Win.Nitro.R513732
Acronis suspicious
McAfee Ransom-Nitro!E59C087E7D76
TACHYON Ransom/W32.DN-Nitro.62976
VBA32 Ransom.MSIL.Nitro.Heur
Malwarebytes Generic.Ransom.FileCryptor.DDS
Rising Trojan.Generic/MSIL@AI.100 (RDM.MSIL:NHes7PoGjbyZSVlLO6XZFQ)
SentinelOne Static AI – Malicious PE
Fortinet MSIL/Filecoder.43CF!tr.ransom
BitDefenderTheta Gen:NN.ZemsilF.34796.dm0@aCPypGm
AVG Win32:RansomX-gen [Ransom]
Panda Trj/GdSda.A
CrowdStrike win/malicious_confidence_90% (D)

How to remove Generic.Ransom.FileCryptor.DDS?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Worm:Win32/Korgo.V”?

The Worm:Win32/Korgo.V is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

Worm.Win32.Vobfus.dlcn (file analysis)

The Worm.Win32.Vobfus.dlcn is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Win32/Adware.InternetAntivirus removal instruction

The Win32/Adware.InternetAntivirus is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

TrojanDownloader:Win32/Unruy.A removal instruction

The TrojanDownloader:Win32/Unruy.A is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Trojan:MSIL/Zusy.RDF!MTB removal guide

The Trojan:MSIL/Zusy.RDF!MTB is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

About “Win32:Sality-KYG” infection

The Win32:Sality-KYG is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago