Ransom

Generic.Ransom.GandCrab.66E2407F removal instruction

Malware Removal

The Generic.Ransom.GandCrab.66E2407F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.66E2407F virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.coin
nomoreransom.bit
dns2.soprodns.ru
gandcrab.bit

How to determine Generic.Ransom.GandCrab.66E2407F?


File Info:

crc32: CAFA4B29
md5: ea9cedcd186623fe754731a983af2fdd
name: EA9CEDCD186623FE754731A983AF2FDD.mlw
sha1: a3d996a2f07e79a3c1fb936b9c2d0776385b27de
sha256: 4bfe4c1587bf66b0c649aa94c5639405b17a1795c19c1505ff55d87fe9cc882b
sha512: c2009183e55365a5b77bd103b005420267ef6060fc5b5f1be51e2532e0581ceffc1b5cbc848593f0537d20b670aac89e816d09a1d29ddd5bc1065994ef644c55
ssdeep: 1536:RZZZZZZZZZZZZpXzzzzzzzzzzzzV9rXounV98hbHnAwfMqqU+2bbbAV2/S2Lkvd:NBounVyFHpfMqqDL2/Lkvd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.66E2407F also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31290
MicroWorld-eScanGeneric.Ransom.GandCrab.66E2407F
FireEyeGeneric.mg.ea9cedcd186623fe
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGeneric.Ransom.GandCrab.66E2407F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Ransomware.Gandcrab-6667060-0
K7AntiVirusTrojan ( 0053d33d1 )
BitDefenderGeneric.Ransom.GandCrab.66E2407F
K7GWTrojan ( 00526c7b1 )
Cybereasonmalicious.d18662
BitDefenderThetaGen:NN.ZexaF.34590.eyW@aO66Ongi
CyrenW32/S-700f8b9d!Eldorado
SymantecRansom.GandCrab!g4
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMIU
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Gandcrab-6502432-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Inject.eyyizx
RisingRansom.GandCrab!1.B8D6 (RDMK:cmRtazp7utdGcbYeNEn920GmLclV)
Ad-AwareGeneric.Ransom.GandCrab.66E2407F
EmsisoftGeneric.Ransom.GandCrab.66E2407F (B)
ComodoTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Filecoder.Win32.7162
TrendMicroRansom.Win32.GANDCRAB.SMIU
McAfee-GW-EditionBehavesLike.Win32.RansomGandcrab.kh
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/GandCrab-A
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.Generic.bzhzc
MaxSecureTrojan-Ransom.GandCrab.C
AviraTR/Dropper.Gen
Antiy-AVLHackTool/Win32.Inject
MicrosoftRansom:Win32/Gandcrab
GridinsoftMalware.Win32.Gen.cc!s1
ArcabitGeneric.Ransom.GandCrab.66E2407F
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FileCoder.R221681
Acronissuspicious
McAfeeRansom-Gandcrab!EA9CEDCD1866
MAXmalware (ai score=86)
VBA32BScope.Trojan.Chapak
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
APEXMalicious
TencentMalware.Win32.Gencirc.10b0b456
YandexTrojan.GenAsa!N5wkFSylebY
eGambitTrojan.Generic
FortinetW32/GandCrab.B!tr.ransom
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.9D5B.Malware.Gen

How to remove Generic.Ransom.GandCrab.66E2407F?

Generic.Ransom.GandCrab.66E2407F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment