Ransom

Generic.Ransom.GandCrab.3189A25C malicious file

Malware Removal

The Generic.Ransom.GandCrab.3189A25C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.3189A25C virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the Gandcrab malware family
  • Anomalous binary characteristics

How to determine Generic.Ransom.GandCrab.3189A25C?


File Info:

name: 068C76C3F85F3DFE0033.mlw
path: /opt/CAPEv2/storage/binaries/d5bb89c504db55c0433a9973611135f403a9cdf6ce5b23641666c25e7992655f
crc32: 874BA58F
md5: 068c76c3f85f3dfe003397bb2d77534c
sha1: a200ee626f61eb574ff751d1da69739516880c37
sha256: d5bb89c504db55c0433a9973611135f403a9cdf6ce5b23641666c25e7992655f
sha512: 3719e44f0d76fd19509a0c334d1678b32e37db293ee5dac52694ed17b3f8cfb3a9187ba5efe9b99e30f10878722900e5317051c0a835f2fe43112ab14ac6b947
ssdeep: 1536:5ZZZZZZZZZZZZpzZZZZZZZZZZZZpXzzzzzzzzzzzzV9rXouuV78hbHnAoMqqU+22:jBouuV4FHVMqqDL2/LgHkc2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E046C1EA3E1B293E1E25BB9FA743D65486E3D10BB1597DB599398462D630F02C3B303
sha3_384: 22af722a268b6fe9446abec0fef9cf804d5a2312414c3fc648fbb3b879d564ac140fd8df2ff8d50328412cada229508e
timestamp: 2018-02-20 17:28:57

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.3189A25C also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGeneric.Ransom.GandCrab.3189A25C
FireEyeGeneric.mg.068c76c3f85f3dfe
ALYacGeneric.Ransom.GandCrab.3189A25C
CylanceUnsafe
VIPREGeneric.Ransom.GandCrab.3189A25C
SangforRansom.Win32.Gandcrab_1.se
CrowdStrikewin/malicious_confidence_100% (D)
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.GandCrab.B
TrendMicro-HouseCallMal_Xed-7
ClamAVWin.Ransomware.Gandcrab-6667060-0
BitDefenderGeneric.Ransom.GandCrab.3189A25C
CynetMalicious (score: 100)
Ad-AwareGeneric.Ransom.GandCrab.3189A25C
EmsisoftGeneric.Ransom.GandCrab.3189A25C (B)
ComodoHeur.Corrupt.PE@1z141z3
DrWebTrojan.Encoder.24384
TrendMicroMal_Xed-7
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
APEXMalicious
GDataGeneric.Ransom.GandCrab.3189A25C
MAXmalware (ai score=82)
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt.c
ArcabitGeneric.Ransom.GandCrab.3189A25C
MicrosoftRansom:Win32/GandCrab.AE
GoogleDetected
McAfeeGenericRXLX-RO!068C76C3F85F
MalwarebytesMalware.AI.1896438207
RisingRansom.GandCrab!1.B8D6 (CLASSIC)
IkarusTrojan-Ransom.GandCrab
FortinetW32/GandCrab.B!tr.ransom
Cybereasonmalicious.3f85f3

How to remove Generic.Ransom.GandCrab.3189A25C?

Generic.Ransom.GandCrab.3189A25C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment