Ransom

Generic.Ransom.Sodinokibi.D928A67A removal instruction

Malware Removal

The Generic.Ransom.Sodinokibi.D928A67A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Sodinokibi.D928A67A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • A scripting utility was executed
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Generic.Ransom.Sodinokibi.D928A67A?


File Info:

crc32: 3161AA56
md5: 487c9853e8f7c2749d108a410c37ca27
name: tmp_a_to5do
sha1: 6e3af7c749c175dd4f33b11d2acc10ef2af2afd3
sha256: 56b1a9153ba2d1db44f642f44cfef000cc9958bde31b808d6d524058b67de48b
sha512: b99745884c11e213fed0867053e7622ca453fa44ac2f8eb964b8bfcf9f0a0600b8c47a2e6d0a85ddfe29c39b41867313852f1a3aac210e6e144bc01186d5e847
ssdeep: 1536:ikB/Ih3+7QuoZVQgf5GV2jSzGpAyZ4ICS4AwnfxRk/LlVft+TMe8wXG:gFW7gSzKDin5SLbo99X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Sodinokibi.D928A67A also known as:

MicroWorld-eScanDeepScan:Generic.Ransom.Sodinokibi.D928A67A
FireEyeGeneric.mg.487c9853e8f7c274
Qihoo-360HEUR/QVM20.1.21AF.Malware.Gen
McAfeeRansom-Sodnkibi!487C9853E8F7
CylanceUnsafe
K7AntiVirusTrojan ( 0054d99c1 )
BitDefenderDeepScan:Generic.Ransom.Sodinokibi.D928A67A
K7GWTrojan ( 0054d99c1 )
Cybereasonmalicious.3e8f7c
TrendMicroRansom.Win32.SODINOKIB.SMTH
F-ProtW32/Kryptik.AKW.gen!Eldorado
SymantecRansom.Cryptolocker
ESET-NOD32a variant of Win32/Filecoder.Sodinokibi.H
APEXMalicious
ClamAVWin.Ransomware.Sodinokibi-7013612-0
KasperskyHEUR:Trojan-Ransom.Win32.Gen.gen
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
RisingRansom.Sodin!8.10CD8 (RDMK:cmRtazpcA1Ys0Eyx4ChEkaNb3+oj)
Endgamemalicious (high confidence)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Encoder.28004
ZillyaTrojan.Filecoder.Win32.14118
Invinceaheuristic
FortinetW32/Sodinokibi.B!tr.ransom
Trapminesuspicious.low.ml.score
EmsisoftDeepScan:Generic.Ransom.Sodinokibi.D928A67A (B)
CyrenW32/Kryptik.AKW.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[Ransom]/Win32.Gen
ArcabitDeepScan:Generic.Ransom.Sodinokibi.D928A67A
AegisLabTrojan.Win32.Gen.j!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Gen.gen
MicrosoftRansom:Win32/Sodinokibi.DSB!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Ransom.R290570
Acronissuspicious
VBA32BScope.Trojan.DelShad
ALYacDeepScan:Generic.Ransom.Sodinokibi.D928A67A
Ad-AwareDeepScan:Generic.Ransom.Sodinokibi.D928A67A
MalwarebytesRansom.Sodinokibi
TrendMicro-HouseCallRansom.Win32.SODINOKIB.SMTH
TencentMalware.Win32.Gencirc.115db758
YandexTrojan.Filecoder!y9oiwgE9Gww
SentinelOneDFI – Malicious PE
GDataDeepScan:Generic.Ransom.Sodinokibi.D928A67A
BitDefenderThetaGen:NN.ZexaF.34130.huW@ayVR36m
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.Ransom.Sodinokibi.D928A67A?

Generic.Ransom.Sodinokibi.D928A67A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment