Ransom

Ransom.HydraCrypt.28 (B) malicious file

Malware Removal

The Ransom.HydraCrypt.28 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.HydraCrypt.28 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Appends a known CryptoShield ransomware file extension to files that have been encrypted
  • Anomalous binary characteristics

How to determine Ransom.HydraCrypt.28 (B)?


File Info:

crc32: DE67C9B2
md5: ac10ff952f5a9dc92989799caeaf6a93
name: AC10FF952F5A9DC92989799CAEAF6A93.mlw
sha1: 0a12841bf53ac466c48959443edf1d47ad2178f4
sha256: d257e7e7e69fe31888a9bbbeee2939ba3e95e457688b4414249944b63f8e9292
sha512: 2f7b549a7ebefbba0b1c453b509c04a1510201e62f161c81edc70d0cd13e49b9cf3ea68be29c9af3cbe6ddd32753a30a139a5fb1fdfe738bb7a01956a8054345
ssdeep: 1536:fBR/vHPB3a5FXDNdoKk7P08Bv2KDpUjMww49NMzppbj6QegI:7RK5FzN07rntUAD49N2mQbI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001 - 2017
FileVersion: 7, 4, 1, 8
CompanyName: Windows Protect
ProductName: Windows Protect
ProductVersion: 7, 4, 1, 8
FileDescription: Windows Protect
OriginalFilename: winlogon.exe
Translation: 0x0860 0x03a8

Ransom.HydraCrypt.28 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056e7311 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader23.53303
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ6
ALYacGen:Variant.Ransom.HydraCrypt.28
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.17405
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0056e7311 )
Cybereasonmalicious.52f5a9
SymantecRansom.Troldesh!gm
ESET-NOD32a variant of Win32/GenKryptik.UAI
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Fury.pe
BitDefenderGen:Variant.Ransom.HydraCrypt.28
NANO-AntivirusTrojan.Win32.Fury.eveudy
MicroWorld-eScanGen:Variant.Ransom.HydraCrypt.28
TencentWin32.Trojan.Fury.Lmke
Ad-AwareGen:Variant.Ransom.HydraCrypt.28
ComodoMalware@#3ocv7n20u3z4a
BitDefenderThetaGen:NN.ZexaF.34142.fu0@au!2!Pci
VIPREBehavesLike.Win32.Malware.rwx (mx-v)
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.nc
FireEyeGeneric.mg.ac10ff952f5a9dc9
EmsisoftGen:Variant.Ransom.HydraCrypt.28 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Fury.dv
AviraHEUR/AGEN.1113593
Antiy-AVLTrojan/Generic.ASMalwS.22BB829
MicrosoftRansom:Win32/Shieldcrypt.A
ArcabitTrojan.Ransom.HydraCrypt.28
GDataGen:Variant.Ransom.HydraCrypt.28
McAfeeTrojan-FLGJ!AC10FF952F5A
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Fury
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/CI.A
RisingTrojan.Generic@ML.96 (RDML:EydDiB52hMC4/10aOF9/Bg)
YandexTrojan.Fury!sycrdgDFbE0
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.FOCI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.HydraCrypt.28 (B)?

Ransom.HydraCrypt.28 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment