Ransom

Generic.Ransom.WCryG.7FB0BD9A (file analysis)

Malware Removal

The Generic.Ransom.WCryG.7FB0BD9A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.WCryG.7FB0BD9A virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Generic.Ransom.WCryG.7FB0BD9A?


File Info:

crc32: 4F459AFC
md5: ad501ae078043e4b2f9203f95171fa0d
name: AD501AE078043E4B2F9203F95171FA0D.mlw
sha1: 3e0c4d3374dec279c3f139594b27df18e5db1342
sha256: 07c48c74c0de0556cf51afb0af88dfa74c326ccf2cc1be4d5c3a716119592fa0
sha512: a8df4b07e913028601af53907f82431602ec4c4b743fec69cb5db88ff3f789f50be3c5183c8feb58ec1d0ff64ddd549e9ef3e51f8581f46676054db8cc24acdc
ssdeep: 3072:uxHvYbcjpyRV5h5DXi9aNDLwP0Q/RJdDWos3XhCW8EKuY2klu63vy:uxPXpyL5zi9FHDWHHhCWLKnzf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Cryptology
InternalName: noncorrupt
FileVersion: 1.7
CompanyName: Cryptology
ProductName: noncorrupt doub cordis
ProductVersion: 1.7
FileDescription: noncorrupt sockeroos ess
OriginalFilename: noncorrupt.exe
Translation: 0x0409 0x04b0

Generic.Ransom.WCryG.7FB0BD9A also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Encoder.18078
MicroWorld-eScanDeepScan:Generic.Ransom.WCryG.7FB0BD9A
FireEyeGeneric.mg.ad501ae078043e4b
McAfeeRansomware-GIX!AD501AE07804
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051cfe21 )
BitDefenderDeepScan:Generic.Ransom.WCryG.7FB0BD9A
K7GWTrojan ( 0051cfe21 )
Cybereasonmalicious.078043
BitDefenderThetaGen:NN.ZexaF.34590.ju0@aWHpuMgi
SymantecML.Attribute.HighConfidence
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.8b45978d
NANO-AntivirusTrojan.Win32.Zerber.eviods
AegisLabTrojan.Win32.Generic.4!c
RisingRansom.Cerber!8.3058 (TFE:1:hwWTIAs4wlG)
Ad-AwareDeepScan:Generic.Ransom.WCryG.7FB0BD9A
SophosML/PE-A + Mal/Cerber-C
ComodoMalware@#1905rspxp5li0
F-SecureHeuristic.HEUR/AGEN.1121409
McAfee-GW-EditionRansomware-GIX!AD501AE07804
EmsisoftDeepScan:Generic.Ransom.WCryG.7FB0BD9A (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Zerber.dhi
AviraHEUR/AGEN.1121409
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Cerber.A
ArcabitDeepScan:Generic.Ransom.WCryG.7FB0BD9A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Ransom.WCryG.7FB0BD9A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C2280711
Acronissuspicious
VBA32Trojan-Ransom.Zerber
ALYacDeepScan:Generic.Ransom.WCryG.7FB0BD9A
MalwarebytesMalware.AI.3889658858
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.EZQC
TencentWin32.Trojan.Generic.Lohk
YandexTrojan.GenAsa!gbMRQ3Oqwdw
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.3ff

How to remove Generic.Ransom.WCryG.7FB0BD9A?

Generic.Ransom.WCryG.7FB0BD9A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment