Ransom

About “Generic.Ransom.Hiddentear.A.56D4761C” infection

Malware Removal

The Generic.Ransom.Hiddentear.A.56D4761C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Hiddentear.A.56D4761C virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the StormKitty malware family
  • Binary compilation timestomping detected

How to determine Generic.Ransom.Hiddentear.A.56D4761C?


File Info:

name: A3295052BC7FD9E663A3.mlw
path: /opt/CAPEv2/storage/binaries/2c2a1a9c7e980851fb72a962411a1881e2c826a8c17383803e9d9ba2e6dea691
crc32: 38A250F0
md5: a3295052bc7fd9e663a32e8faeb83e01
sha1: 5fd5dc4f9f66b8eaa8d18d5ee366960c858b7834
sha256: 2c2a1a9c7e980851fb72a962411a1881e2c826a8c17383803e9d9ba2e6dea691
sha512: 95384f823862dc0d034b67f7a30419ee09bcf4899d886826a07982c3ad843cb11caeecfffbc3eba5c712f83ffc54f473d7743e561b1e2da6784dd9f3cc71675a
ssdeep: 6144:qeZKNlWc/gqXKq8+RigIWU+Ydm0UAN0kEma9bm:JZKNlWcBaq8+RnWm0UANvEm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB545B1437EC4B26E2FE5FB9E4B1112583B1B463752EDB8F5C9A28EE1D523809510BB3
sha3_384: abd14cccecc461a1838dbd3405a36c0af967d9005042f97133c266d6d72c6c794e3875d334dc837d5ab09a3eeb246abd
ep_bytes: ff250020400000000000000000000000
timestamp: 2048-01-28 02:14:53

Version Info:

Comments: I am not responsible for all your actions, the program is designed to test for PC vulnerabilities
CompanyName: © DarkBlood Malware project
FileDescription: Virus software stealer for stealing accounts, wallets, etc.
FileVersion: 1.0.0.0
InternalName: DarkStealer.exe
LegalCopyright: Copyright DarkBlood Malware © 2021
LegalTrademarks: DarkBlood
OriginalFilename: DarkStealer.exe
ProductName: DarkStealer
ProductVersion: 1.1.0.0
Assembly Version: 1.1.0.0
Translation: 0x0000 0x04b0

Generic.Ransom.Hiddentear.A.56D4761C also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Shelpak.4!c
MicroWorld-eScanGeneric.Ransom.Hiddentear.A.56D4761C
FireEyeGeneric.mg.a3295052bc7fd9e6
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGeneric.Ransom.Hiddentear.A.56D4761C
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0056c3751 )
AlibabaTrojan:MSIL/CryptInject.415cb35d
K7GWPassword-Stealer ( 0056c3751 )
Cybereasonmalicious.2bc7fd
BitDefenderThetaGen:NN.ZemsilF.34806.sm0@ayNv8Em
CyrenW32/Stealer.AK.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/PSW.Agent.RXP
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Shelpak.gen
BitDefenderGeneric.Ransom.Hiddentear.A.56D4761C
AvastWin32:KeyloggerX-gen [Trj]
TencentWin32.Trojan.Generic.Ljjt
Ad-AwareGeneric.Ransom.Hiddentear.A.56D4761C
EmsisoftGeneric.Ransom.Hiddentear.A.56D4761C (B)
DrWebTrojan.PWS.StealerNET.74
VIPREGeneric.Ransom.Hiddentear.A.56D4761C
McAfee-GW-EditionFareit-FWC!A3295052BC7F
SophosMal/Generic-S
IkarusTrojan-Spy.Echelon
JiangminTrojan.MSIL.aluhv
AviraHEUR/AGEN.1247913
Antiy-AVLTrojan/Generic.ASMalwS.33C
MicrosoftTrojan:MSIL/CryptInject!MTB
ViRobotTrojan.Win32.S.Formbook.294912
ZoneAlarmHEUR:Trojan.MSIL.Shelpak.gen
GDataGeneric.Ransom.Hiddentear.A.56D4761C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Formbook.C4262574
Acronissuspicious
McAfeeFareit-FWC!A3295052BC7F
MAXmalware (ai score=100)
VBA32Trojan.MSIL.Shelpak
MalwarebytesSpyware.AgentTesla.Generic
RisingStealer.Agent!1.D483 (CLASSIC)
YandexTrojan.Shelpak!3ygUXk3TYsk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.103650238.susgen
FortinetMSIL/Agent.RXP!tr.pws
AVGWin32:KeyloggerX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Ransom.Hiddentear.A.56D4761C?

Generic.Ransom.Hiddentear.A.56D4761C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment