Ransom

Generic.Ransom.GandCrab.54F36FCC information

Malware Removal

The Generic.Ransom.GandCrab.54F36FCC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.54F36FCC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com

How to determine Generic.Ransom.GandCrab.54F36FCC?


File Info:

crc32: 4DC0E939
md5: 7f1106af8d4ae2d3f7209c865c03a89e
name: 7F1106AF8D4AE2D3F7209C865C03A89E.mlw
sha1: 7bdbd0629b2b5268b2a40272558698131cf8716e
sha256: 8f2bb7e82ad819787186521c468ef8a5971d60f4df6ef6130562bedc43ee2d5e
sha512: 219f0ba11b10aa7ae24dbca8342f215058a9d8b4022066c978467f7e8de27e9ac7e71e3c4a3b7d5738f6f63849b9b1a6e8eb8aea0f9452aa2fdab3de5db2aae7
ssdeep: 1536:2ZZZZZZZZZZZZpXzzzzzzzzzzzzADypczUk+lkZJngWMqqU+2bbbAV2/S2OvvdZ:ld5BJHMqqDL2/Ovvdr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.54F36FCC also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.GandCrab.54F36FCC
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGeneric.Ransom.GandCrab.54F36FCC
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Ransomware.Gandcrab-6667060-0
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGeneric.Ransom.GandCrab.54F36FCC
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f8d4ae
CyrenW32/S-7cea76e9!Eldorado
SymantecRansom.GandCrab
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Gandcrab-6667060-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Encoder.eytbdj
ViRobotTrojan.Win32.GandCrab.71680
TencentMalware.Win32.Gencirc.10b0bc40
Ad-AwareGeneric.Ransom.GandCrab.54F36FCC
SophosML/PE-A + Mal/GandCrab-L
ComodoTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Encoder.30802
ZillyaTrojan.Filecoder.Win32.7196
TrendMicroRansom_GANDCRAB.SM1
McAfee-GW-EditionBehavesLike.Win32.RansomGandcrab.lh
MaxSecureTrojan.Malware.121218.susgen
FireEyeGeneric.mg.7f1106af8d4ae2d3
EmsisoftGeneric.Ransom.GandCrab.54F36FCC (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cabqs
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLHackTool/Win32.Inject
MicrosoftRansom:Win32/Gandcrab
GridinsoftRansom.Win32.Gen.cc!s1
ArcabitGeneric.Ransom.GandCrab.54F36FCC
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransom.R222567
Acronissuspicious
McAfeeTrojan-FPDG!7F1106AF8D4A
VBA32BScope.Trojan.Chapak
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
TrendMicro-HouseCallRansom_GANDCRAB.SM1
RisingRansom.Gandcrab!8.F355 (TFE:dGZlOgJXO+ROPSfquw)
YandexTrojan.GenAsa!qHIhniD54fs
IkarusTrojan-Ransom.GandCrab
eGambitTrojan.Generic
FortinetW32/GandCrab.B!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34590.eyW@auTsjxoi
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.9D5B.Malware.Gen

How to remove Generic.Ransom.GandCrab.54F36FCC?

Generic.Ransom.GandCrab.54F36FCC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment