Ransom

About “Generic.Ransom.GandCrab.D510C31D” infection

Malware Removal

The Generic.Ransom.GandCrab.D510C31D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.D510C31D virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.coin
nomoreransom.bit
dns2.soprodns.ru
gandcrab.bit

How to determine Generic.Ransom.GandCrab.D510C31D?


File Info:

crc32: 4DF43E3B
md5: d59e87e94a44510416e2b45d2a4cf752
name: D59E87E94A44510416E2B45D2A4CF752.mlw
sha1: a6a72276e81678f0aaa3fcc4c2586646321d1e3a
sha256: 03a178251c26c86b518a785027f99295fb4f8c797a5aee9f1b2e6f75433890db
sha512: 6c5c8ea3e334cfe8acc8d3127dc30587218088c693108260b33509a12145e21858ee382c54d8daaf16d59517f02d06c01873294d6c3f541f49dde0a3f9befd12
ssdeep: 768:7XIxo9TZkKFN7Vf3sohEJH5co/iej2JWOkKgTiGMqWNUMFAHJ9E3lvd6s:TIxo9TNFA9coqlWOkKgdMqqUM2Lkvd6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.D510C31D also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.28632
MicroWorld-eScanGeneric.Ransom.GandCrab.D510C31D
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360HEUR/QVM20.1.9D5B.Malware.Gen
McAfeeRansom-Gandcrab!D59E87E94A44
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Ransomware.Gandcrab-6667060-0
K7AntiVirusTrojan ( 0053d33d1 )
BitDefenderGeneric.Ransom.GandCrab.D510C31D
K7GWTrojan ( 00526c7b1 )
Cybereasonmalicious.94a445
BitDefenderThetaGen:NN.ZexaF.34590.eyW@aOJn2Dk
CyrenW32/S-10388f1c!Eldorado
SymantecRansom.GandCrab!g4
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Gandcrab-6502432-0
KasperskyTrojan-Ransom.Win32.GandCrypt.jcc
NANO-AntivirusTrojan.Win32.Inject.eyyizx
TencentMalware.Win32.Gencirc.10b0af12
Ad-AwareGeneric.Ransom.GandCrab.D510C31D
TACHYONRansom/W32.GandCrab.71168
EmsisoftGeneric.Ransom.GandCrab.D510C31D (B)
ComodoTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Generic.Win32.597553
TrendMicroRansom.Win32.GANDCRAB.SMIU
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.kt
FireEyeGeneric.mg.d59e87e94a445104
SophosML/PE-A + Troj/GandCrab-A
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.Generic.cyzvz
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt.c
MicrosoftRansom:Win32/GandCrab.E
GridinsoftRansom.Win32.Ransom.oa!s1
ArcabitGeneric.Ransom.GandCrab.D510C31D
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.jcc
GDataGeneric.Ransom.GandCrab.D510C31D
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Ransom_gandcrab.C3001087
Acronissuspicious
VBA32BScope.Trojan.Chapak
ALYacGeneric.Ransom.GandCrab.D510C31D
MAXmalware (ai score=86)
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMIU
RisingRansom.GandCrab!1.B8D6 (CLASSIC)
YandexTrojan.GenAsa!N5wkFSylebY
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetW32/GandCrab.B!tr.ransom
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan-Ransom.GandCrab.C

How to remove Generic.Ransom.GandCrab.D510C31D?

Generic.Ransom.GandCrab.D510C31D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment