Ransom

Dropped:Generic.Ransom.GoldenEye.D4CEDEF4 information

Malware Removal

The Dropped:Generic.Ransom.GoldenEye.D4CEDEF4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Ransom.GoldenEye.D4CEDEF4 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Unusual version info supplied for binary

How to determine Dropped:Generic.Ransom.GoldenEye.D4CEDEF4?


File Info:

crc32: 110F3FC5
md5: d13faf29f8e815618bde3e8ff2e8c76e
name: D13FAF29F8E815618BDE3E8FF2E8C76E.mlw
sha1: 66e2857d06204486841d415684b19b2b99df6bf3
sha256: 9dcd2e56bf074be745a9b9997766f1971461d1fb2eeb7b2c29a3eb575c6a7489
sha512: 7b3684d1919a25d556bdc547cd010251840657b4bff01eb806389ecbc102f643b3477eb56432d46f8b6d6629249f767e23db2b1b5e683f296cdf21629d0b44ee
ssdeep: 1536:hzW+UWvxY9Qgu9iLoLSGnHfks5g6pBlerRROIN1tE4+gugquZi:hzW+DiC9iLo+GnHf95ajRq4ggq8
type: PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 8.00.7600.16385 (win7_rtm.090713-1255)
CompanyName: Sabaddi Group
ProductName: Windowsxae Internet Explorer
ProductVersion: 8.00.7600.16385
FileDescription: NJRAT Setup
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Dropped:Generic.Ransom.GoldenEye.D4CEDEF4 also known as:

K7AntiVirusTrojan ( 004e19001 )
DrWebTrojan.Siggen7.57150
CynetMalicious (score: 99)
ALYacDropped:Generic.Ransom.GoldenEye.D4CEDEF4
CylanceUnsafe
ZillyaTrojan.Generic.Win32.277178
AlibabaRansom:Win32/Petya.74a2b4dd
K7GWTrojan ( 004e19001 )
Cybereasonmalicious.9f8e81
CyrenW32/Injector.PEQY-5235
SymantecRansom.Petya
ESET-NOD32Win32/Diskcoder.Petya.A
APEXMalicious
AvastMBR:Ransom-C [Trj]
ClamAVWin.Ransomware.Petya-6992434-0
KasperskyTrojan-Ransom.Win32.Petr.aqv
BitDefenderDropped:Generic.Ransom.GoldenEye.D4CEDEF4
NANO-AntivirusTrojan.Win32.Diskcoder.fhbqwx
MicroWorld-eScanDropped:Generic.Ransom.GoldenEye.D4CEDEF4
TencentMalware.Win32.Gencirc.10ce47e6
Ad-AwareDropped:Generic.Ransom.GoldenEye.D4CEDEF4
SophosMal/Generic-S
ComodoMalware@#2ka4untaugfpw
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Worm.ch
FireEyeGeneric.mg.d13faf29f8e81561
EmsisoftDropped:Generic.Ransom.GoldenEye.D4CEDEF4 (B)
JiangminAdWare.Generic.svgg
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.24AB156
MicrosoftRansom:Win32/Petya.A
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDropped:Generic.Ransom.GoldenEye.D4CEDEF4
McAfeeArtemis!D13FAF29F8E8
MAXmalware (ai score=84)
VBA32TrojanRansom.Petr
MalwarebytesRansom.Petya
RisingRansom.MBBlocker!8.31B7 (CLOUD)
YandexTrojan.GenAsa!24tXwvlyW3Y
FortinetW32/Petya.A!tr.ransom
AVGMBR:Ransom-C [Trj]

How to remove Dropped:Generic.Ransom.GoldenEye.D4CEDEF4?

Dropped:Generic.Ransom.GoldenEye.D4CEDEF4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment