Ransom

Generic.Ransom.GandCrab.D73F519F removal guide

Malware Removal

The Generic.Ransom.GandCrab.D73F519F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.D73F519F virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.coin
nomoreransom.bit
dns2.soprodns.ru
gandcrab.bit

How to determine Generic.Ransom.GandCrab.D73F519F?


File Info:

crc32: D60CD42A
md5: fd48bde20bfa93840e046d33bbf97bd8
name: FD48BDE20BFA93840E046D33BBF97BD8.mlw
sha1: 2e72d4350984c95069903cb259e0641ebb49f58a
sha256: f93f70a4bc0b2c0c158a5a115d0f3293eedbd7a71d72005a15ef0230ba8cb549
sha512: 548e03a052a515ac858c84bc58df823381a2f4cba67b2f574bb33b0828b78f8ea514672750aabd0b5a0bf997f39f72ac21142a745a3e1a1cf21ee523611dd5d6
ssdeep: 1536:SZZZZZZZZZZZZpXzzzzzzzzzzzzV9rXounV98hbHnAEMqqU+2bbbAV2/S2LNmHk:0BounVyFHFMqqDL2/LgHkc2
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.D73F519F also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.GandCrab.D73F519F
FireEyeGeneric.mg.fd48bde20bfa9384
ALYacGeneric.Ransom.GandCrab.D73F519F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Ransomware.Gandcrab-6667060-0
K7AntiVirusTrojan ( 0053d33d1 )
BitDefenderGeneric.Ransom.GandCrab.D73F519F
K7GWTrojan ( 0053d33d1 )
Cybereasonmalicious.20bfa9
CyrenW32/S-69916e6d!Eldorado
SymantecRansom.GandCrab!g4
APEXMalicious
ClamAVWin.Ransomware.Gandcrab-6502432-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Inject.eyyizx
RisingRansom.GandCrab!1.B8D6 (RDMK:cmRtazpi2jPIbSXy8cLQX1IyrrEm)
Ad-AwareGeneric.Ransom.GandCrab.D73F519F
EmsisoftGeneric.Ransom.GandCrab.D73F519F (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Encoder.24384
ZillyaTrojan.Filecoder.Win32.7540
TrendMicroRansom.Win32.GANDCRAB.SMILB
McAfee-GW-EditionBehavesLike.Win32.RansomGandcrab.nm
SophosML/PE-A + Mal/Palevo-B
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bzhzc
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=89)
Antiy-AVLHackTool/Win32.Inject
MicrosoftRansom:Win32/GandCrab.E
GridinsoftRansom.Win32.Filecoder.bot!s1
ArcabitGeneric.Ransom.GandCrab.D73F519F
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.Ransom.GandCrab.D73F519F
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gandcrab.R255229
Acronissuspicious
McAfeeRansom-Gandcrab!FD48BDE20BFA
TACHYONRansom/W32.GandCrab.99840.B
VBA32BScope.Trojan.Chapak
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMILB
TencentTrojan.Win32.Gandcrab.e
YandexTrojan.GenAsa!N5wkFSylebY
IkarusTrojan-Ransom.GandCrab
eGambitTrojan.Generic
FortinetW32/GandCrab.B!tr.ransom
BitDefenderThetaAI:Packer.433266BC1C
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.9D5B.Malware.Gen

How to remove Generic.Ransom.GandCrab.D73F519F?

Generic.Ransom.GandCrab.D73F519F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment