Ransom

WannaCry.Ransom.Encrypt.DDS removal guide

Malware Removal

The WannaCry.Ransom.Encrypt.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WannaCry.Ransom.Encrypt.DDS virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

How to determine WannaCry.Ransom.Encrypt.DDS?


File Info:

crc32: 799309BE
md5: 517a6b1306a3f8b1965053564a1c1564
name: 517A6B1306A3F8B1965053564A1C1564.mlw
sha1: 36513a64a2f1d621366e898df09a7d4675992c2d
sha256: 0466c30d11752dc81e27fd20d12ba53b418ee88fc4fed4e1a1b41a2016ede294
sha512: 561a9631ee24e91c3409172864e310fa98032270561573b0b7c5c1d1f9148a8a3a38041824c8738ff47d23fbf1ba46daa671ba635f8b3923ac6e915056fa801e
ssdeep: 98304:whqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2g3z:whqPe1Cxcxk3ZAEUadzR8yc4gj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: lhdfrgui.exe
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: Microsoftxae Disk Defragmenter
OriginalFilename: lhdfrgui.exe
Translation: 0x0409 0x04b0

WannaCry.Ransom.Encrypt.DDS also known as:

BkavW32.FamVT.DeagezLC.Trojan
K7AntiVirusExploit ( 0050d7a31 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.11432
CynetMalicious (score: 100)
CAT-QuickHealRansomware.WannaCry.IRG1
ALYacTrojan.Ransom.WannaCryptor
CylanceUnsafe
ZillyaTrojan.WannaCry.Win32.1
SangforRansom.Win32.Wannacry_0.se
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/dark.ali1000040
K7GWExploit ( 0050d7a31 )
Cybereasonmalicious.306a3f
BaiduWin32.Worm.Rbot.a
CyrenW32/Trojan.ZTSA-8671
SymantecRansom.Wannacry
ESET-NOD32Win32/Exploit.CVE-2017-0147.A
ZonerTrojan.Win32.59562
APEXMalicious
AvastSf:WNCryLdr-A [Trj]
ClamAVWin.Ransomware.WannaCry-6313787-0
KasperskyTrojan-Ransom.Win32.Wanna.m
BitDefenderTrojan.Ransom.WannaCryptor.H
NANO-AntivirusTrojan.Win32.Wanna.eovgam
ViRobotTrojan.Win32.WannaCry.3723264.A
SUPERAntiSpywareRansom.WannaCrypt/Variant
MicroWorld-eScanTrojan.Ransom.WannaCryptor.H
TencentMalware.Win32.Gencirc.10b3d198
Ad-AwareTrojan.Ransom.WannaCryptor.H
SophosMal/Generic-R + Mal/Wanna-A
ComodoTrojWare.Win32.Exploit.CVE-2017-0147.C@8oq0ji
F-SecureTrojan:W32/WannaCry.D
BitDefenderThetaGen:NN.ZexaF.34628.Jt1@aePsbmpi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_WCRY.SM2
McAfee-GW-EditionBehavesLike.Win32.RansomWannaCry.wc
FireEyeGeneric.mg.517a6b1306a3f8b1
EmsisoftTrojan-Ransom.WanaCrypt0r (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.WanaCry.i
AviraTR/Ransom.IZ
eGambitTrojan.Generic
Antiy-AVLTrojan[Ransom]/Win32.Scatter
KingsoftWin32.Heur.KVM005.a.(kcloud)
MicrosoftRansom:Win32/WannaCrypt.H
GridinsoftMalware.Win32.Pack.30058!se
ArcabitTrojan.Ransom.WannaCryptor.H
AegisLabTrojan.Win32.Wanna.toNz
ZoneAlarmTrojan-Ransom.Win32.Wanna.m
GDataWin32.Trojan-Ransom.WannaCry.D
TACHYONRansom/W32.WannaCry.Zen
AhnLab-V3Trojan/Win32.WannaCryptor.R200572
Acronissuspicious
McAfeeRansom-WannaCry!517A6B1306A3
MAXmalware (ai score=100)
VBA32TrojanRansom.Wanna
MalwarebytesWannaCry.Ransom.Encrypt.DDS
PandaTrj/RansomCrypt.I
TrendMicro-HouseCallRansom_WCRY.SM2
RisingRansom.Wanna!8.E7B2 (TFE:dGZlOgVr8t/MABEOqA)
YandexTrojan.GenAsa!VW7HnU9046M
IkarusTrojan-Ransom.Wannacryptor
MaxSecureTrojan-Ransom.Win32.Wanna.m
FortinetW32/Generic.AC.3F0684!tr
AVGSf:WNCryLdr-A [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.WannaCry.HykCjlsA

How to remove WannaCry.Ransom.Encrypt.DDS?

WannaCry.Ransom.Encrypt.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment