Ransom

Ransom.HydraCrypt.1 (file analysis)

Malware Removal

The Ransom.HydraCrypt.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.HydraCrypt.1 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Ransom.HydraCrypt.1?


File Info:

crc32: FC0D775E
md5: ac6d3c5c0c4ac6c8649b3aac03b756d9
name: AC6D3C5C0C4AC6C8649B3AAC03B756D9.mlw
sha1: a5be314a777a61f7d0eed84b15d5ef25fe2c4676
sha256: 8d6d88321dbd629e5b2fbcd69e0bf4d0c19f916fc850f3ba3baca5873bc6bfb2
sha512: 97d5428995b6ca1d10a84eb5eda02873675962a52992f93b5d2477cd9e5a0e42edb807f960d2f30e28ba60940fbc807910dc7ea8097275cd36e6b77f1f86c2c0
ssdeep: 3072:tMhjrCs7VYMJfNgLVmsqoJ0bnLQyWrHGloFoaIl+pcdZv73eD4i0cavrJS4cVa6:tMhuMJFuTQnkyWrmWRIUc2D4iekN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 1995 - 2005
FileVersion: 1,14,10,4
CompanyName: SynSoft, Corporation.
ProductName: YsdTwabl
ProductVersion: 1,14,10,4
FileDescription: pWiGwkR
OriginalFilename: aQLhsGlYcMim.exe
Translation: 0x0410 0x04b0

Ransom.HydraCrypt.1 also known as:

BkavW32.AIDetect.malware1
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.HydraCrypt.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/EncPk.46805e00
K7GWTrojan ( 0051f8a21 )
K7AntiVirusTrojan ( 0051f8a21 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KIOCVBV
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Ransom.HydraCrypt.1
MicroWorld-eScanGen:Variant.Ransom.HydraCrypt.1
TencentWin32.Trojan.Crypt.Lohx
Ad-AwareGen:Variant.Ransom.HydraCrypt.1
SophosMal/Generic-R + Mal/EncPk-ALY
ComodoMalware@#351o87jb7vgoy
BitDefenderThetaAI:Packer.9333E7A221
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.ac6d3c5c0c4ac6c8
EmsisoftGen:Variant.Ransom.HydraCrypt.1 (B)
AviraTR/Crypt.ZPACK.imrvo
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Ransom.HydraCrypt.1
AegisLabTrojan.Win32.HydraCrypt.4!c
GDataGen:Variant.Ransom.HydraCrypt.1
AhnLab-V3Malware/Win32.Generic.C2369280
Acronissuspicious
McAfeeArtemis!AC6D3C5C0C4A
MAXmalware (ai score=100)
VBA32Malware-Cryptor.General.3
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Crypto!8.364 (CLOUD)
YandexTrojan.Agent!ba7hJ7hdQD8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.10445116.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASOoA

How to remove Ransom.HydraCrypt.1?

Ransom.HydraCrypt.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment