Ransom

Generic.Ransom.GandCrab.6470B743 removal tips

Malware Removal

The Generic.Ransom.GandCrab.6470B743 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.6470B743 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.coin
nomoreransom.bit
dns2.soprodns.ru
gandcrab.bit

How to determine Generic.Ransom.GandCrab.6470B743?


File Info:

crc32: 18D596B8
md5: d835f0d067f0ce5e5738ef3011e364ad
name: D835F0D067F0CE5E5738EF3011E364AD.mlw
sha1: 4c12e7082be38199b8e2963620fa6c47c2cb5386
sha256: 93c94b311af623c1ce2930904c94cae88bddd481c9b95f5b59836f5c537b3948
sha512: e795778c202b80a6cb61e3f80e8be4a12b6a24d676707325e24fe7b48dc518f49f76e9d103420a8c55df16929478728665e186e829b732a226a4b51036195624
ssdeep: 1536:5ZZZZZZZZZZZZpXzzzzzzzzzzzzV9rXounV98hbHnAEMqqU+2bbbAV2/S2LNmHk:lBounVyFHFMqqDL2/LgHkc2
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.6470B743 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.GandCrab.6470B743
ALYacGeneric.Ransom.GandCrab.6470B743
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Ransomware.Gandcrab-6667060-0
K7AntiVirusTrojan ( 0053d33d1 )
BitDefenderGeneric.Ransom.GandCrab.6470B743
K7GWTrojan ( 0053d33d1 )
Cybereasonmalicious.067f0c
CyrenW32/S-69916e6d!Eldorado
SymantecRansom.GandCrab!g4
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Gandcrab-6502432-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Inject.eyyizx
TencentTrojan.Win32.Gandcrab.e
Ad-AwareGeneric.Ransom.GandCrab.6470B743
EmsisoftGeneric.Ransom.GandCrab.6470B743 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Encoder.24384
ZillyaTrojan.Filecoder.Win32.7540
TrendMicroRansom.Win32.GANDCRAB.SMILB
McAfee-GW-EditionBehavesLike.Win32.RansomGandcrab.nm
FireEyeGeneric.mg.d835f0d067f0ce5e
SophosML/PE-A + Mal/Palevo-B
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bzhzc
AviraTR/Crypt.XPACK.Gen3
eGambitTrojan.Generic
MAXmalware (ai score=80)
Antiy-AVLHackTool/Win32.Inject
MicrosoftRansom:Win32/GandCrab.E
GridinsoftRansom.Win32.Filecoder.bot!s1
ArcabitGeneric.Ransom.GandCrab.6470B743
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.Ransom.GandCrab.6470B743
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gandcrab.R255229
Acronissuspicious
McAfeeRansom-Gandcrab!D835F0D067F0
TACHYONRansom/W32.GandCrab.99840.B
VBA32BScope.Trojan.Chapak
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMILB
RisingRansom.GandCrab!1.B8D6 (CLASSIC)
YandexTrojan.GenAsa!N5wkFSylebY
IkarusTrojan-Ransom.GandCrab
FortinetW32/GandCrab.B!tr.ransom
BitDefenderThetaAI:Packer.433266BC1C
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.9D5B.Malware.Gen

How to remove Generic.Ransom.GandCrab.6470B743?

Generic.Ransom.GandCrab.6470B743 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment