Ransom

About “Ransom:MSIL/HiddenTear.A” infection

Malware Removal

The Ransom:MSIL/HiddenTear.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/HiddenTear.A virus can do?

  • At least one IP Address, Domain, or File Name was found in a crypto call

How to determine Ransom:MSIL/HiddenTear.A?


File Info:

crc32: 07F04769
md5: 64ed26a47e85b603719c5a84c488cb72
name: 64ED26A47E85B603719C5A84C488CB72.mlw
sha1: 36a08cb2cbccbca26d02bb42f8bb8423223a3379
sha256: 2d128440ed7e666349f9c900edefb193685faa97136c4300b66a97de1ee6c537
sha512: f9457d189e252d7534df6aa16d7789585aa7b1a0a24f7f1faf7611aa43630b6bde63b22264b638ba70761a18e178ad2edbe77d49b3056aba1c27e31f16e7fcda
ssdeep: 1536:Vsli3sH/PrHk3rdkImbobyecdSSdR6ss0QGNc5XFcH5L3wp6UFGAUXdwd0PjN3w:Vs+sH/w3+ImbobyDdSOLdZbJwYX
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Inteloc Inc. (C) 1966-2017
Assembly Version: 1.8.3.1
InternalName: Alone2.exe
FileVersion: 2.0.7.4
CompanyName: Inteloc Inc
LegalTrademarks: Inteloc Industrial (II)
Comments: Education software for people
ProductName: Education software for people
ProductVersion: 2.0.7.4
FileDescription: Elembor Inteloc
OriginalFilename: Alone2.exe

Ransom:MSIL/HiddenTear.A also known as:

K7AntiVirusTrojan ( 004ddf631 )
Elasticmalicious (high confidence)
DrWebTrojan.EncoderNET.HiddenTear.1
CynetMalicious (score: 85)
ALYacTrojan.Ransom.3301
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.6079
SangforTrojan.Win32.Save.a
AlibabaRansom:MSIL/HiddenTear.0ac3dc0a
K7GWTrojan ( 004ddf631 )
Cybereasonmalicious.47e85b
SymantecRansom.HiddenTear!g1
ESET-NOD32a variant of MSIL/Filecoder.AK
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusTrojan.Win32.Filecoder.erpryn
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
TencentWin32.Trojan.Generic.Wqnl
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
SophosMal/Cryptear-A
ComodoMalware@#gza8exapxec8
BitDefenderThetaGen:NN.ZemsilF.34608.Mm0@ae9rpTn
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HIDDENTEARTHREE.A
McAfee-GW-EditionRansomware-FTD!64ED26A47E85
FireEyeGeneric.mg.64ed26a47e85b603
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:MSIL/HiddenTear.A
ArcabitTrojan.Ransom.REntS.Gen.1
GDataGen:Heur.Ransom.REntS.Gen.1
McAfeeRansomware-FTD!64ED26A47E85
MAXmalware (ai score=99)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HIDDENTEARTHREE.A
RisingTrojan.Shyape!1.B5E8 (CLOUD)
YandexTrojan.Agent!vClSg1RpXYc
IkarusTrojan.MSIL.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.AK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HwMAzI0A

How to remove Ransom:MSIL/HiddenTear.A?

Ransom:MSIL/HiddenTear.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment