Ransom

Ransom.DearCry removal instruction

Malware Removal

The Ransom.DearCry is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.DearCry virus can do?

  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Appends a known multi-family ransomware file extension to files that have been encrypted
  • Anomalous binary characteristics

How to determine Ransom.DearCry?


File Info:

crc32: D294DD91
md5: 6be28a4523984698e7154671f73361bf
name: 6BE28A4523984698E7154671F73361BF.mlw
sha1: b974375ef0f6dcb6ce30558df2ed8570bf1ad642
sha256: fdec933ca1dd1387d970eeea32ce5d1f87940dfb6a403ab5fc149813726cbd65
sha512: c3a44431e8cbb76d75ea2a1caca6fe77dfbd2a9565da918620433d415d396c08394ecb1c6454fc69661d61683711e53b60a69435e25518a04e81c20136f62f20
ssdeep: 24576:C5Nv2SkWFP/529IC8u2bAs0NIzkQS+KpPbEasBY2iKDl1fpxkLVZgMCST:oB70s9yjE62iIl1fpxkLVZgMCA
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.DearCry also known as:

K7AntiVirusTrojan ( 005790ee1 )
DrWebTrojan.Encoder.33592
CynetMalicious (score: 85)
ALYacGen:Variant.Ransom.DearCry.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/DoejoCrypt.086e48a8
K7GWTrojan ( 005790ee1 )
CyrenW32/Ransom.TNVJ-5084
ESET-NOD32a variant of Win32/Filecoder.DearCry.A
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Dearcry-9840778-0
KasperskyHEUR:Trojan-Ransom.Win32.Encoder.gen
BitDefenderGen:Variant.Ransom.DearCry.1
ViRobotTrojan.Win32.Z.Dearcry.1322521
MicroWorld-eScanGen:Variant.Ransom.DearCry.1
TencentWin32.Trojan.Filecoder.Wtdy
Ad-AwareGen:Variant.Ransom.DearCry.1
SophosMal/Generic-S + Troj/Ransom-GFE
F-SecureTrojan.TR/FileCoder.hzatm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGen:Variant.Ransom.DearCry.1
EmsisoftGen:Variant.Ransom.DearCry.1 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/FileCoder.hzatm
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/DoejoCrypt.A
GridinsoftRansom.Win32.Wacatac.oa!s1
ArcabitTrojan.Ransom.DearCry.1
AegisLabTrojan.Win32.Encoder.j!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Encoder.gen
GDataWin32.Trojan-Ransom.DearCry.B
AhnLab-V3Ransomware/Win.DoejoCrypt.R371582
McAfeeRansom-DearCry!6BE28A452398
MAXmalware (ai score=100)
MalwarebytesRansom.DearCry
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.VSNW0CC21
RisingRansom.DearCry!1.D3C7 (CLOUD)
IkarusTrojan-Ransom.FileCrypter
FortinetW32/DearCry.OGE!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HwoC3RsA

How to remove Ransom.DearCry?

Ransom.DearCry removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment