Categories: Ransom

Generic.Ransom.GandCrab.5AC58AD0 (file analysis)

The Generic.Ransom.GandCrab.5AC58AD0 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.5AC58AD0 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • CAPE detected the Gandcrab malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Ransom.GandCrab.5AC58AD0?


File Info:

name: 22FE8DF09F9A52B379F7.mlwpath: /opt/CAPEv2/storage/binaries/f89d7dbea8f1d44adb9c20b1d900a8999f65067325b1fb4ff12b63231975a3efcrc32: 91AF7F0Cmd5: 22fe8df09f9a52b379f7c303d1f9a29dsha1: d2ce73a2a41853705095049dbadd04263ed3b3f2sha256: f89d7dbea8f1d44adb9c20b1d900a8999f65067325b1fb4ff12b63231975a3efsha512: 4f92ea16a1b3d7e37c21587210677027a4a1b3ea3c34ef642f3d61bb20324bfba94b11956e34d67c4ba632194a804e03553c4dedebfc588daa14b6dce68648c3ssdeep: 1536:2RRRRRRRRRRRRBVKIRU1RXFUjNMCA7MqqU+2bbbAV2/S2Ovvd67Ad:EjUfQw7MqqDL2/OvvdBtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T140936E00B1E1B117E0F39BBA9BB97E3940BD3D206729ABCB1BD5594ACC268F01935753sha3_384: 9449c594e39eb77d6051b41346914a2465719f30bf00e79f1c78b8fd27ccd7381569ca4b0ec72f17808fef99abec455bep_bytes: 558bec83ec4c68e8030000ff1598a046timestamp: 2018-03-04 18:10:15

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.5AC58AD0 also known as:

Bkav W32.AIDetectMalware
DrWeb Trojan.Encoder.30802
MicroWorld-eScan Generic.Ransom.GandCrab.5AC58AD0
ClamAV Win.Ransomware.Gandcrab-6667060-0
FireEye Generic.mg.22fe8df09f9a52b3
CAT-QuickHeal Trojan.Mauvaise.SL1
ALYac Generic.Ransom.GandCrab.5AC58AD0
Malwarebytes Ransom.GandCrab
VIPRE Generic.Ransom.GandCrab.5AC58AD0
Sangfor Ransom.Win32.Gandcrab_1.se
K7AntiVirus Trojan ( 00526c7b1 )
K7GW Trojan ( 00526c7b1 )
CrowdStrike win/malicious_confidence_100% (D)
BitDefenderTheta Gen:NN.ZexaF.36164.fyW@aO3CHrai
Cyren W32/GandCrab.BP.gen!Eldorado
Symantec Ransom.GandCrab!g4
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Filecoder.GandCrab.H
APEX Malicious
Cynet Malicious (score: 100)
Kaspersky VHO:Trojan-Ransom.Win32.GandCrypt.gen
BitDefender Generic.Ransom.GandCrab.5AC58AD0
Avast Win32:RansomX-gen [Ransom]
Tencent Trojan-Ransom.Win32.GandCrab.16000553
Sophos Mal/GandCrab-L
F-Secure Trojan.TR/Dropper.Gen
Zillya Trojan.Filecoder.Win32.29444
TrendMicro Ransom_GANDCRAB.SM1
McAfee-GW-Edition BehavesLike.Win32.Trojan.mm
Trapmine malicious.moderate.ml.score
Emsisoft Generic.Ransom.GandCrab.5AC58AD0 (B)
Ikarus Trojan-Ransom.GandCrab
GData Generic.Ransom.GandCrab.5AC58AD0
Avira TR/Dropper.Gen
MAX malware (ai score=87)
Antiy-AVL Trojan[Ransom]/Win32.GandCrab
Xcitium TrojWare.Win32.Ransom.GandCrab.B@7kn2ff
Arcabit Generic.Ransom.GandCrab.5AC58AD0
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Ransom:Win32/Gandcrab
Google Detected
AhnLab-V3 Trojan/Win32.Gandcrab.R224768
McAfee GenericRXFC-SK!22FE8DF09F9A
VBA32 BScope.Trojan.Chapak
Cylance unsafe
TrendMicro-HouseCall Ransom_GANDCRAB.SM1
Rising Ransom.GandCrab!1.B8D6 (CLASSIC)
Yandex Trojan.GenAsa!qHIhniD54fs
SentinelOne Static AI – Malicious PE
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/GandCrab.B!tr.ransom
AVG Win32:RansomX-gen [Ransom]
DeepInstinct MALICIOUS

How to remove Generic.Ransom.GandCrab.5AC58AD0?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “MSIL/TrojanDropper.Agent.BVT”?

The MSIL/TrojanDropper.Agent.BVT is considered dangerous by lots of security experts. When this infection is active,…

11 hours ago

Should I remove “Generic.Dacic.94CCEEA9.A.A4A6DA47”?

The Generic.Dacic.94CCEEA9.A.A4A6DA47 is considered dangerous by lots of security experts. When this infection is active,…

11 hours ago

Malware.AI.524217860 removal tips

The Malware.AI.524217860 is considered dangerous by lots of security experts. When this infection is active,…

11 hours ago

Trojan:Win32/Koutodoor.F removal tips

The Trojan:Win32/Koutodoor.F is considered dangerous by lots of security experts. When this infection is active,…

12 hours ago

How to remove “Malware.AI.1412460714”?

The Malware.AI.1412460714 is considered dangerous by lots of security experts. When this infection is active,…

12 hours ago

Generic.Dacic.8952383F.A.5EC8C34B removal instruction

The Generic.Dacic.8952383F.A.5EC8C34B is considered dangerous by lots of security experts. When this infection is active,…

12 hours ago