Ransom

Ransom:Win32/HiddenTear removal tips

Malware Removal

The Ransom:Win32/HiddenTear is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/HiddenTear virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/HiddenTear?


File Info:

crc32: 00A39656
md5: 80143152971ee77d14bb77c8d10346ec
name: upload_file
sha1: 6c6e9ebe1e11714bd4c3584fc5b732ccfb782a05
sha256: 7860832a25f403c43865c00bd072fa58b2da66bc81152eec30582ad0a72932e6
sha512: 133f5a81542f5475597b5d2dea84af932ff49df5286a27dc9ce0dfdaa200d52f6cec8fd9f44c07e86e2585195c278874953e4dcd15a5b1a7845f704125e0c36b
ssdeep: 12288:CeXzSAp2noO6CvOJHLc3vYndhqXtMLPCu4QRxEI:CejCnoFOqHLc2dhGMLPCu4QRxL
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: TODO:
FileVersion: 1,0,0,0
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.0
FileDescription: TODO:
Translation: 0x0000 0x04e4

Ransom:Win32/HiddenTear also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43938747
McAfeeGeneric-FAWW!80143152971E
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 0052438a1 )
BitDefenderTrojan.GenericKD.43938747
K7GWTrojan ( 0052438a1 )
Cybereasonmalicious.2971ee
ArcabitTrojan.Generic.D29E73BB
InvinceaMal/Generic-R + Mal/EncPk-ANL
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/HiddenTear.c9e6893b
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.43938747
EmsisoftTrojan.GenericKD.43938747 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Encoder.32725
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HiddenTear.R002C0DIU20
McAfee-GW-EditionBehavesLike.Win32.Yahlover.gc
FireEyeGeneric.mg.80143152971ee77d
SophosMal/EncPk-ANL
SentinelOneDFI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_70%
MAXmalware (ai score=82)
MicrosoftRansom:Win32/HiddenTear.gen
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.43938747
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.TrojanPSW.Banker
ALYacTrojan.GenericKD.43938747
MalwarebytesRansom.HiddenTear
ESET-NOD32a variant of Win32/Packed.Obsidium.AS
TrendMicro-HouseCallRansom_HiddenTear.R002C0DIU20
RisingTrojan.Generic@ML.94 (RDML:qizetFRirkk2dVctJx8/Yg)
IkarusTrojan.Win32.Obsidium
FortinetW32/Generic!tr
BitDefenderThetaGen:NN.ZexaF.34282.Aq3@aWR3vpf
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM19.1.465B.Malware.Gen

How to remove Ransom:Win32/HiddenTear?

Ransom:Win32/HiddenTear removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment