Ransom

Generic.Ransom.GandCrab.80A4E52F removal

Malware Removal

The Generic.Ransom.GandCrab.80A4E52F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.80A4E52F virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the Gandcrab malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

How to determine Generic.Ransom.GandCrab.80A4E52F?


File Info:

name: FE8240E1579958C1513B.mlw
path: /opt/CAPEv2/storage/binaries/63a07105b2dcbd37295ee8c45e32e6f6d707224b85387cd4dc3c0845e06d3342
crc32: 37FD52EB
md5: fe8240e1579958c1513bc6bff8b93249
sha1: 13bf4b02aaa879acbb3b6319540b7742d152c72d
sha256: 63a07105b2dcbd37295ee8c45e32e6f6d707224b85387cd4dc3c0845e06d3342
sha512: d3bd9cae04bc22d2751525bb7a4b00d3bcebd6286cf1de8ecbafaaae73585bcfc5e1e4423f18c32c632f91e59ede62455769a9afb5ab14aabde5298250d5bd1c
ssdeep: 1536:R555555555555pfnqnCGbtZ5bfYLMqqU+2bbbAV2/S2xr3IdE8mne0Avu5r++yyH:Xqn1D5b2MqqDL2/xr3IdE8we0Avu5r+E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F9348112DF08133E2E3FF3BAB757A2779393F25382975565066147E1E660024A36B8F
sha3_384: 549259ff1ca581ffe8a737b48bb0e2c296d2ed7277d74e4d9534e7e1a3d25943f07b5252a218dc5c1131f68faefee70e
ep_bytes: 558bece8e0fdffff6a00ff156891c600
timestamp: 2018-01-27 00:46:47

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.80A4E52F also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.GandCrypt.H!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fe8240e1579958c1
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeRansomware-GJP!FE8240E15799
CylanceUnsafe
SangforRansom.Win32.Gandcrab_1.se
K7AntiVirusTrojan ( 0053d33d1 )
AlibabaRansom:Win32/GandCrab.ali1020008
K7GWTrojan ( 0053d33d1 )
Cybereasonmalicious.157995
CyrenW32/GandCrab.AR.gen!Eldorado
SymantecRansom.GandCrab!g4
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Gandcrab-6502430-0
KasperskyTrojan-Ransom.Win32.GandCrypt.jnp
BitDefenderGeneric.Ransom.GandCrab.80A4E52F
MicroWorld-eScanGeneric.Ransom.GandCrab.80A4E52F
AvastWin32:RansomX-gen [Ransom]
TencentWin32.Trojan.Filecoder.Egny
SophosML/PE-A + Troj/GandCrab-A
ComodoTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
TrendMicroRansom_GANDCRAB.SMALY-4
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
EmsisoftGeneric.Ransom.GandCrab.80A4E52F (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Jorik.afpe
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Generic.ASMalwS.3520205
GridinsoftRansom.Win32.Gandcrab.sa
MicrosoftRansom:Win32/GandCrab.A
ViRobotTrojan.Win32.Z.Gandcrab.90112.ACY
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.jnp
GDataWin32.Trojan-Ransom.GandCrab.C
AhnLab-V3Trojan/Win32.Agentb.R219506
BitDefenderThetaGen:NN.ZexaF.34182.fyW@aO5i@uki
ALYacGeneric.Ransom.GandCrab.80A4E52F
MAXmalware (ai score=82)
VBA32BScope.Trojan.Chapak
MalwarebytesRansom.GandCrab
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-4
RisingRansom.GandCrab!1.B8D6 (CLOUD)
YandexTrojan.GenAsa!PQWJX9MqkkE
IkarusTrojan-Ransom.GandCrab
FortinetW32/GandCrab.A!tr.ransom
AVGWin32:RansomX-gen [Ransom]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Ransom.GandCrab.80A4E52F?

Generic.Ransom.GandCrab.80A4E52F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment