Ransom

About “Generic.Ransom.Small.629D3AB9” infection

Malware Removal

The Generic.Ransom.Small.629D3AB9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Small.629D3AB9 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Anomalous binary characteristics

How to determine Generic.Ransom.Small.629D3AB9?


File Info:

crc32: 3D1D60ED
md5: 10faa73c8d8e5525b1505add7c7f6bfb
name: 10FAA73C8D8E5525B1505ADD7C7F6BFB.mlw
sha1: abbeb0fe6147ff53a09204cd0ae9737d48c9f46c
sha256: 5349fcf2b31c33591101744b3fbf8ede0af4714f950e80e6c20884af51abf231
sha512: 00fb2bd67c7326351ede8a5bc84e911c9c47a2413462fccb7d3d70d7fb37c69500d3f1aae9fb378d209e0abc82cbf3a7dc99dec4bde2c5f298e0a93330010042
ssdeep: 192:doNpQSqvnZ3+SALPu6w0okyrxNbThspt4ZpuamKvKLCdRBbbh+N9o5HWcn:S+SqR+SALW6yXNbTypWZpDpba8Wc
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2018
Assembly Version: 1.0.0.0
InternalName: ssvchost.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
LegalTrademarks:
Comments:
ProductName: Death
ProductVersion: 1.0.0.0
FileDescription: Death
OriginalFilename: ssvchost.exe

Generic.Ransom.Small.629D3AB9 also known as:

K7AntiVirusTrojan ( 004ddf631 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10598
CynetMalicious (score: 99)
ALYacGeneric.Ransom.Small.629D3AB9
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7757
SangforTrojan.Win32.Save.a
K7GWTrojan ( 004ddf631 )
Cybereasonmalicious.c8d8e5
CyrenW32/Ransom.IQ.gen!Eldorado
SymantecRansom.HiddenTear!g1
ESET-NOD32a variant of MSIL/Filecoder.AK
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGeneric.Ransom.Small.629D3AB9
NANO-AntivirusTrojan.Win32.Encoder.fcfbjt
MicroWorld-eScanGeneric.Ransom.Small.629D3AB9
TencentMsil.Trojan.Msil.Dyqs
Ad-AwareGeneric.Ransom.Small.629D3AB9
SophosMal/Generic-R + Troj/Cryptear-A
ComodoMalware@#23kzh1p53pxrs
BitDefenderThetaGen:NN.ZemsilF.34670.am0@aiGPjBc
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_RAMSIL.SM
McAfee-GW-EditionRansomware-FTD!10FAA73C8D8E
FireEyeGeneric.mg.10faa73c8d8e5525
EmsisoftGeneric.Ransom.Small.629D3AB9 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129970
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:MSIL/Cryptolocker.PDF!MTB
ArcabitGeneric.Ransom.Small.629D3AB9
AegisLabTrojan.Win32.Generic.4!c
GDataMSIL.Trojan-Ransom.Cryptear.W
AhnLab-V3Malware/Win32.RL_Ransom_ramsil.C4080377
McAfeeRansomware-FTD!10FAA73C8D8E
MAXmalware (ai score=98)
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_RAMSIL.SM
RisingRansom.HiddenTear!8.DC9E (CLOUD)
IkarusTrojan-Ransom.HiddenTear
FortinetW32/Cryptear.A!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HwMAEpsA

How to remove Generic.Ransom.Small.629D3AB9?

Generic.Ransom.Small.629D3AB9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment