Ransom

Generic.Ransom.GandCrab.C0633F0D removal guide

Malware Removal

The Generic.Ransom.GandCrab.C0633F0D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.C0633F0D virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.coin
nomoreransom.bit
dns2.soprodns.ru
gandcrab.bit

How to determine Generic.Ransom.GandCrab.C0633F0D?


File Info:

crc32: EBC9B2C7
md5: bd44e98ef371cd5f18cc45b996a99ea0
name: BD44E98EF371CD5F18CC45B996A99EA0.mlw
sha1: eb823759a77e17ad1808364e5acd59a93939b3fa
sha256: c9eb0365bfad644d3570f549ba3241e1b05bf48eecc163ff7ad2e5eba4fd9bdc
sha512: fbc956249c14ee726fe29229026e856470b0ea35738dc31ab96ec2866d1b071f03b0261787256d75e8ff64491b8a62ecfc794ff75dceec32dcc21227ca293ae3
ssdeep: 768:1XIxo9TZkKFN7Vf3sohEJH5co/iej2JWOkKgTiGMqWNUMFAHJ9E3lvd6s:xIxo9TNFA9coqlWOkKgdMqqUM2Lkvd6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.C0633F0D also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.GandCrab.C0633F0D
FireEyeGeneric.mg.bd44e98ef371cd5f
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Win32/Trojan.Ransom.GandCrab.AF
McAfeeRansom-Gandcrab!BD44E98EF371
CylanceUnsafe
ZillyaTrojan.Generic.Win32.597553
SangforWin.Ransomware.Gandcrab-6667060-0
K7AntiVirusTrojan ( 0053d33d1 )
BitDefenderGeneric.Ransom.GandCrab.C0633F0D
K7GWTrojan ( 00526c7b1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/S-10388f1c!Eldorado
SymantecRansom.GandCrab!g4
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Gandcrab-6502432-0
KasperskyTrojan-Ransom.Win32.GandCrypt.jcc
AlibabaRansom:Win32/GandCrab.d38f9627
NANO-AntivirusTrojan.Win32.Inject.eyyizx
ViRobotTrojan.Win32.Z.Gandcrab.71168.AUM
SUPERAntiSpywareRansom.GandCrab/Variant
RisingRansom.GandCrab!1.B8D6 (CLOUD)
Ad-AwareGeneric.Ransom.GandCrab.C0633F0D
SophosMal/Generic-R + Troj/GandCrab-A
ComodoTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader27.28632
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.GANDCRAB.SMIU
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.kt
EmsisoftGeneric.Ransom.GandCrab.C0633F0D (B)
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.Generic.cyzvz
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt.c
MicrosoftRansom:Win32/GandCrab.E
GridinsoftRansom.Win32.Ransom.oa!s1
ArcabitGeneric.Ransom.GandCrab.C0633F0D
AegisLabTrojan.Win32.GandCrypt.tpV8
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.jcc
GDataGeneric.Ransom.GandCrab.C0633F0D
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Ransom_gandcrab.C3001087
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.eyW@aOJn2Dk
ALYacGeneric.Ransom.GandCrab.C0633F0D
TACHYONRansom/W32.GandCrab.71168
VBA32BScope.Trojan.Chapak
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMIU
TencentMalware.Win32.Gencirc.10b0af12
YandexTrojan.GenAsa!N5wkFSylebY
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetW32/GandCrab.B!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.ef371c
AvastWin32:RansomX-gen [Ransom]
MaxSecureTrojan-Ransom.GandCrab.C

How to remove Generic.Ransom.GandCrab.C0633F0D?

Generic.Ransom.GandCrab.C0633F0D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment