Ransom

Generic.Ransom.Small.531C9129 malicious file

Malware Removal

The Generic.Ransom.Small.531C9129 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Small.531C9129 virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Appends a known CryLocker ransomware file extension to files that have been encrypted
  • Creates a known Fakben ransomware decryption instruction / key file.

How to determine Generic.Ransom.Small.531C9129?


File Info:

crc32: DCED9FE0
md5: a324a5a96906fbaf675bc1699fc59d33
name: A324A5A96906FBAF675BC1699FC59D33.mlw
sha1: b94276b9e50b104275a4bb31ab5f2b014c02f562
sha256: 4e9c0723b07b629cb48fde29f9fded0839ba1ab803f43273255b38d508c1340e
sha512: 3713fe99fbcee04684c2a6e034b87468699aad654ef202314e2c6404af0144fa1b6c72864fecab07f665d0aeb56ab40462cc64dfccb9b61077c173cd72a10490
ssdeep: 192:div6McG1tAUTLtGAGKuEbylY26uE4Jz+9afh:ov6TG1tHTLtMn6l4o9uh
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Small.531C9129 also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Encoder.16733
MicroWorld-eScanDeepScan:Generic.Ransom.Small.531C9129
FireEyeGeneric.mg.a324a5a96906fbaf
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005451b81 )
BitDefenderDeepScan:Generic.Ransom.Small.531C9129
K7GWTrojan ( 005451b81 )
BitDefenderThetaGen:NN.ZexaF.34590.amGfa819PZpi
SymantecRansom.CryptoTorLocker
TotalDefenseWin32/Ransom.A!generic
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Encoder.ezasxn
RisingRansom.Sorikrypt!8.8822 (CLOUD)
Ad-AwareDeepScan:Generic.Ransom.Small.531C9129
SophosMal/Generic-S
ComodoTrojWare.Win32.Kryptik.ER@4o1ar2
F-SecureTrojan.TR/Crypt.ULPM.Gen
ZillyaTrojan.Filecoder.Win32.8115
McAfee-GW-EditionGeneric.cui
EmsisoftDeepScan:Generic.Ransom.Small.531C9129 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.caxbf
eGambitUnsafe.AI_Score_98%
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
MicrosoftRansom:Win32/Sorikrypt
ArcabitDeepScan:Generic.Ransom.Small.531C9129
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Ransom.Small.531C9129
CynetMalicious (score: 100)
McAfeeGeneric.cui
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.Q
TencentWin32.Trojan.Raas.Auto
YandexTrojan.GenAsa!FJ4YibNxi0E
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Xorist.DD8C!tr.ransom
AVGWin32:Malware-gen
Cybereasonmalicious.96906f
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM11.1.3AB2.Malware.Gen

How to remove Generic.Ransom.Small.531C9129?

Generic.Ransom.Small.531C9129 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment