Ransom

Generic.Ransom.Snatch.008D840C malicious file

Malware Removal

The Generic.Ransom.Snatch.008D840C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Snatch.008D840C virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Snatch.008D840C?


File Info:

crc32: 518EA041
md5: d798ab1ba5511d67c4ec872807571fa1
name: D798AB1BA5511D67C4EC872807571FA1.mlw
sha1: c68199c0d1f16566afc7d71db95312cebafa9889
sha256: dd23476649d1dbd1561ae7a3b07e9f7ea49a0cde94c467825a523cd645a08e5b
sha512: f9ddccbb241836ba4438b9a8bc563aee8c202fe0bcfa6268b2420caf44ff4854d84a5f1bb2a1f738607021340c11b4778e041cc3aa5937441ae2581dfbde5d6e
ssdeep: 49152:TH8u7grzLPGmvCqerh8pRABLxkWIOGNgMU:TArvPGmv7a8RAB9km
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Snatch.008D840C also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGeneric.Ransom.Snatch.008D840C
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderGeneric.Ransom.Snatch.008D840C
Cybereasonmalicious.ba5511
ESET-NOD32a variant of WinGo/Filecoder.H
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win32.Generic
MicroWorld-eScanGeneric.Ransom.Snatch.008D840C
Ad-AwareGeneric.Ransom.Snatch.008D840C
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34628.XnGfaSCRREd
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.d798ab1ba5511d67
EmsisoftGeneric.Ransom.Snatch.008D840C (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitGeneric.Ransom.Snatch.008D840C
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.Generic
GDataGeneric.Ransom.Snatch.008D840C
AhnLab-V3Trojan/Win32.Wacatac.C4190983
MAXmalware (ai score=87)
MalwarebytesMalware.Heuristic.1003
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazrVaunoGjllkk3Gf4EPTYvx)
MaxSecureTrojan.Malware.300983.susgen
Qihoo-360HEUR/QVM11.1.F67C.Malware.Gen

How to remove Generic.Ransom.Snatch.008D840C?

Generic.Ransom.Snatch.008D840C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment