Ransom

Generic.Ransom.GandCrab.2B3D6A9B removal

Malware Removal

The Generic.Ransom.GandCrab.2B3D6A9B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.2B3D6A9B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipv4bot.whatismyipaddress.com

How to determine Generic.Ransom.GandCrab.2B3D6A9B?


File Info:

crc32: 15B918FF
md5: 46e53858b49a75a4312ef1cf96938b51
name: 46E53858B49A75A4312EF1CF96938B51.mlw
sha1: 374c99b092cd5b277377a32260995455eba18ea6
sha256: 62e46927b14a4da473bc1560cf295f3e4af5208c60bd0cee929e4a959fe13c12
sha512: 5f3c9261868c3956f03b424e0b70d0bd9d2f0e8ae9c3a3e143c8c410c6dbf21e0915f3e617d955899aeed2ed8bfe67d6c938df5d598fdf42da726c07ee9cb40c
ssdeep: 1536:XZZZZZZZZZZZZpXzzzzzzzzzzzzADypczUk+lkZJngWMqqU+2bbbAV2/S2OvvdZ:+d5BJHMqqDL2/Ovvdr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.2B3D6A9B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.GandCrab.2B3D6A9B
FireEyeGeneric.mg.46e53858b49a75a4
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeTrojan-FPDG!46E53858B49A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforWin.Ransomware.Gandcrab-6667060-0
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGeneric.Ransom.GandCrab.2B3D6A9B
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8b49a7
BitDefenderThetaGen:NN.ZexaF.34590.eyW@auTsjxoi
CyrenW32/S-7cea76e9!Eldorado
SymantecRansom.GandCrab
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
TrendMicro-HouseCallRansom_GANDCRAB.SM1
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Gandcrab-6667060-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Gandcrab.d1e91b80
NANO-AntivirusTrojan.Win32.Encoder.eytbdj
ViRobotTrojan.Win32.GandCrab.71680
RisingRansom.GandCrab!1.B8D6 (CLASSIC)
Ad-AwareGeneric.Ransom.GandCrab.2B3D6A9B
EmsisoftGeneric.Ransom.GandCrab.2B3D6A9B (B)
ComodoTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Encoder.30802
ZillyaTrojan.Filecoder.Win32.7196
TrendMicroRansom_GANDCRAB.SM1
McAfee-GW-EditionBehavesLike.Win32.RansomGandcrab.lh
SophosMal/GandCrab-L
APEXMalicious
JiangminTrojan.Generic.cabqs
MaxSecureTrojan.Malware.7164915.susgen
AviraTR/Dropper.Gen
Antiy-AVLHackTool/Win32.Inject
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Gandcrab
GridinsoftRansom.Win32.Gandcrab.oa
ArcabitGeneric.Ransom.GandCrab.2B3D6A9B
SUPERAntiSpywareRansom.GandCrab/Variant
AhnLab-V3Trojan/Win32.Ransom.R222567
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.C
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Chapak
ALYacGeneric.Ransom.GandCrab.2B3D6A9B
MAXmalware (ai score=100)
MalwarebytesRansom.GandCrab
IkarusTrojan-Ransom.GandCrab
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b0bc40
YandexTrojan.GenAsa!qHIhniD54fs
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetW32/GandCrab.B!tr.ransom
WebrootW32.Malware.Gen
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.GandCrab.HxQB67AA

How to remove Generic.Ransom.GandCrab.2B3D6A9B?

Generic.Ransom.GandCrab.2B3D6A9B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment