Ransom

Generic.Ransom.HydraCrypt.FB3030B0 removal instruction

Malware Removal

The Generic.Ransom.HydraCrypt.FB3030B0 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.HydraCrypt.FB3030B0 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a copy of itself
  • Appends a known CryptFile2 ransomware file extension to files that have been encrypted

How to determine Generic.Ransom.HydraCrypt.FB3030B0?


File Info:

crc32: 64B97462
md5: eb8badbd123716722533344dcd84754c
name: EB8BADBD123716722533344DCD84754C.mlw
sha1: 8663ed558b502bbc0f0b16e6348a81652b8de47b
sha256: 069bb7972e000eb976abe00443db896a2f7a487d7627c46e60d5b798821b9f2a
sha512: cd39e7dd7c6952c1558086a445849471fa120ee6c09236b558a56247cf2d8a31c64534e5e4c801e52067b346e90385334f8ec7f3eb10fb820964e09151df2bca
ssdeep: 1536:UoB+zTYnm1LpI0Brl3qe/P5WZ9bNUvDmkx2j+Dltu:nTmB1Bp/BKb+vD7xq+Xu
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Spy_Rasomwares Copyright (C) 2016
InternalName: Spy_Rasomwares
FileVersion: 6,2,8,11
CompanyName: Spy_Rasomwares
ProductVersion: 6,2,8,11
OriginalFilename: Spy_Rasomwares
Transla: 0x0411 0x04e8

Generic.Ransom.HydraCrypt.FB3030B0 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader23.17846
CynetMalicious (score: 100)
ALYacTrojan.Ransom.CryptoMix
CylanceUnsafe
ZillyaAdware.Zonidel.Win32.3
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.d12371
SymantecRansom.CryptXXX
ESET-NOD32Win32/Filecoder.HydraCrypt.D
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Zonidel.djd
BitDefenderDeepScan:Generic.Ransom.HydraCrypt.FB3030B0
NANO-AntivirusTrojan.Win32.Blocker.eiomof
ViRobotTrojan.Win32.Ransom.80896[UPX]
MicroWorld-eScanDeepScan:Generic.Ransom.HydraCrypt.FB3030B0
TencentWin32.Trojan.Raas.Auto
Ad-AwareDeepScan:Generic.Ransom.HydraCrypt.FB3030B0
SophosMal/Generic-S
ComodoMalware@#3a25y67p5gpav
BitDefenderThetaAI:Packer.AEF5C67720
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Virut.qc
FireEyeGeneric.mg.eb8badbd12371672
EmsisoftDeepScan:Generic.Ransom.HydraCrypt.FB3030B0 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Farfli.aub
AviraHEUR/AGEN.1103261
MicrosoftRansom:Win32/HydraCrypt.A
AegisLabTrojan.Win32.Zonidel.4!c
GDataDeepScan:Generic.Ransom.HydraCrypt.FB3030B0
AhnLab-V3Backdoor/Win32.Poison.C2327798
McAfeeArtemis!EB8BADBD1237
MAXmalware (ai score=100)
VBA32BScope.Trojan.Glupteba
PandaTrj/GdSda.A
YandexBackdoor.Poison!psaNHvKm3tI
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/HydraCrypt.D!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.HydraCrypt.FB3030B0?

Generic.Ransom.HydraCrypt.FB3030B0 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment