Ransom

Generic.Ransom.GandCrab4.6DE341AA (file analysis)

Malware Removal

The Generic.Ransom.GandCrab4.6DE341AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab4.6DE341AA virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to modify desktop wallpaper
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.GandCrab4.6DE341AA?


File Info:

crc32: 265CA707
md5: 3fde98f8b1c49b58bd33c9ed61426a8c
name: 3FDE98F8B1C49B58BD33C9ED61426A8C.mlw
sha1: 4ac96253f8675bd2e7be85c876354e89bc3cd8dd
sha256: 65d0cf34f6266eb246b75a9012ba84d9821351f7c9e9e8ffe831e3b68cdcfb56
sha512: 7c1362cf7cc933fd4eca837cc52c4770f99946c94b02b66bfc8b93e81cffbe4a684ff38f35d7f17975af24b6904013663cf0724e3d98c5ca7121e2c96bb56127
ssdeep: 6144:l8HMRjaMIAA+NpKkv3FQvI3e28tCdN9BFQvI3e28tCdN9:lHj6Od3FjNkMN9BFjNkMN9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GandCrab4.6DE341AA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d33d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGeneric.Ransom.GandCrab4.6DE341AA
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.977
SangforWin.Ransomware.Gandcrab-6667060-0
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/GandCrab.cc18e6cd
K7GWTrojan ( 0053d33d1 )
Cybereasonmalicious.8b1c49
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.GandCrab.D
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Gandcrab-6667060-0
KasperskyTrojan-Ransom.Win32.GandCrypt.fbd
BitDefenderGeneric.Ransom.GandCrab4.6DE341AA
NANO-AntivirusTrojan.Win32.GandCrypt.fildxe
ViRobotTrojan.Win32.GandCrab.172032
MicroWorld-eScanGeneric.Ransom.GandCrab4.6DE341AA
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.GandCrab4.6DE341AA
SophosML/PE-A + Troj/Patched-BY
ComodoTrojWare.Win32.Gandcrab.AA@7w10qu
BitDefenderThetaGen:NN.ZexaF.34688.FCW@aGrtuzki
TrendMicroRansom_GANDCRAB.THAOABAH
McAfee-GW-EditionBehavesLike.Win32.Sivis.gm
FireEyeGeneric.mg.3fde98f8b1c49b58
EmsisoftGeneric.Ransom.GandCrab4.6DE341AA (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.afk
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.283A81F
MicrosoftRansom:Win32/GandCrab.MCTQX
AegisLabTrojan.Win32.GandCrypt.tpXu
GDataGeneric.Ransom.GandCrab4.6DE341AA
AhnLab-V3Trojan/Win32.Gandcrab.R239033
McAfeeRansom-GandCrab!3FDE98F8B1C4
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesRansom.GandCrab
PandaGeneric Suspicious
TrendMicro-HouseCallRansom_GANDCRAB.THAOABAH
RisingRansom.GandCrypt!8.F33E (C64:YzY0OlW+HJIgpBhb)
YandexTrojan.GenAsa!HEiK121QQPQ
IkarusTrojan-Ransom.GandCrab
FortinetW32/GandCrab.D!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.GandCrab4.6DE341AA?

Generic.Ransom.GandCrab4.6DE341AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment