Ransom

Generic.Ransom.GandCrab.F42E0FC7 removal tips

Malware Removal

The Generic.Ransom.GandCrab.F42E0FC7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab.F42E0FC7 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • CAPE detected the Gandcrab malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Ransom.GandCrab.F42E0FC7?


File Info:

name: 73049E407195D2B954F3.mlw
path: /opt/CAPEv2/storage/binaries/ff1d366e070478445c0b8b840a82838f41f98722268b3842e53130696d509599
crc32: A48BC92B
md5: 73049e407195d2b954f329db496b1ac9
sha1: 48d065fe6db8972d04379b2b404485534114c998
sha256: ff1d366e070478445c0b8b840a82838f41f98722268b3842e53130696d509599
sha512: 618155b45a102ad17f9c34a00e1703cf9cb6661d54d4c41c5a2e60e7b7147d0e110aaab6d3d5ab03ed1dbd88e35d4836611f44f97f3bb77e6e8ef3e5f0cadd96
ssdeep: 3072:Md5BJOoMqqDL2/OvvdHv3uqz3++OAYWgO:MdJODqqDL6gvdHveqi+GWgO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BC36E1EB3C12373E1D203B6FA6A7DD2961E2D3437555BE304A6807D26139F46A3B782
sha3_384: 5274010d53a75195dcaf60e2342f3d27c49acded8118927624a99c1a9101c3c0b90d10f4cd3c9d3567802b1ff0fab43d
ep_bytes: 558bec83ec4c68e8030000ff1598a000
timestamp: 2020-11-28 18:10:15

Version Info:

0: [No Data]

Generic.Ransom.GandCrab.F42E0FC7 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.GandCrypt.trP9
MicroWorld-eScanGeneric.Ransom.GandCrab.F42E0FC7
FireEyeGeneric.mg.73049e407195d2b9
McAfeeGenericRXLX-RO!73049E407195
MalwarebytesRansom.GandCrab
SangforRansom.Win32.Gandcrab_1.se
K7AntiVirusTrojan ( 005641f81 )
BitDefenderGeneric.Ransom.GandCrab.F42E0FC7
K7GWTrojan ( 005641f81 )
Cybereasonmalicious.07195d
VirITTrojan.Win32.Encoder.BKBW
CyrenW32/S-7cea76e9!Eldorado
SymantecRansom.GandCrab
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
APEXMalicious
ClamAVWin.Packed.Barys-10002063-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/GandCrab.2d67f2d1
NANO-AntivirusTrojan.Win32.Encoder.eytbdj
ViRobotTrojan.Win32.GandCrab.71680
RisingRansom.GandCrab!1.B8D6 (CLASSIC)
EmsisoftGeneric.Ransom.GandCrab.F42E0FC7 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Encoder.35853
ZillyaTrojan.Filecoder.Win32.28075
TrendMicroRansom_GANDCRAB.SMNM
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
Trapminesuspicious.low.ml.score
SophosMal/Palevo-B
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.Generic.cabqs
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=85)
Antiy-AVLHackTool/Win32.Inject
XcitiumTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
MicrosoftRansom:Win32/Gandcrab
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.Ransom.GandCrab.F42E0FC7
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.GANDCRAB.C5341998
BitDefenderThetaGen:NN.ZexaF.36250.h0Z@a8FiuTii
ALYacGeneric.Ransom.GandCrab.F42E0FC7
VBA32BScope.Trojan.Chapak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.SMNM
TencentTrojan-Ransom.Win32.Gandcrab.yb
YandexTrojan.Agent!TDMdWRqjs1I
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GandCrab.B!tr.ransom
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Ransom.GandCrab.F42E0FC7?

Generic.Ransom.GandCrab.F42E0FC7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment