Ransom

Generic.Ransom.Matrix.C9DC3407 removal instruction

Malware Removal

The Generic.Ransom.Matrix.C9DC3407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Matrix.C9DC3407 virus can do?

  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Matrix.C9DC3407?


File Info:

crc32: E873E062
md5: 00b3c199e2af831eaa743aacbe72aeaa
name: 00B3C199E2AF831EAA743AACBE72AEAA.mlw
sha1: ec6f32f1c03e97f6ca30adb2ab10050f0c9ab0aa
sha256: 0c8a167489a9e271a4af5529aeeb0ab28a28ac983a446b6cc185972052362d81
sha512: 5d2aa4ece8783031b8185c0cd31728b752a703684897b24560c04f3df761929a12e58269cf1d509016a10a428ce2548f6ec735c02e8a17324d88db2cbc027742
ssdeep: 24576:g054T8vzLtotO23wVBy5QkBpYzMOY7pOoozujr3YlInf5b7Zed:5Rot9qIDDOY7goozuZnfxZe
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Matrix.C9DC3407 also known as:

K7AntiVirusTrojan ( 00520f2e1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25593
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Matrix
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.8084
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/LockedFile.85917aee
K7GWTrojan ( 00520f2e1 )
Cybereasonmalicious.9e2af8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.LockedFile.D
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Matrix-6502602-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGeneric.Ransom.Matrix.C9DC3407
NANO-AntivirusTrojan.Win32.Encoder.faiwze
ViRobotTrojan.Win32.S.Metrix.1075200
MicroWorld-eScanGeneric.Ransom.Matrix.C9DC3407
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.Matrix.C9DC3407
SophosMal/Generic-R + Troj/Matrix-I
ComodoMalware@#zi444zjxhspx
BitDefenderThetaAI:Packer.F417FF8A21
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.MATRIX.AL
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.00b3c199e2af831e
EmsisoftGeneric.Ransom.Matrix.C9DC3407 (B)
JiangminTrojan.Generic.cbsdl
WebrootW32.Trojan.Gen
AviraTR/FileCoder.miqkq
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitGeneric.Ransom.Matrix.C9DC3407
AegisLabTrojan.Win32.Generic.j!c
GDataWin32.Trojan-Ransom.Matrix.A
AhnLab-V3Trojan/Win32.Matrix.C2428826
McAfeeArtemis!00B3C199E2AF
MAXmalware (ai score=100)
VBA32Trojan.Downloader
MalwarebytesRansom.FileLocker
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.MATRIX.AL
YandexTrojan.GenAsa!6P+4TKkRaKA
IkarusTrojan-Ransom.Matrix
FortinetW32/Matrix.2FFD!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Matrix.C9DC3407?

Generic.Ransom.Matrix.C9DC3407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment