Ransom

Generic.Ransom.GandCrab4.F98669AC removal instruction

Malware Removal

The Generic.Ransom.GandCrab4.F98669AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab4.F98669AC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

www.billerimpex.com
www.macartegrise.eu
www.poketeg.com
perovaphoto.ru
asl-company.ru
www.fabbfoundation.gm
www.perfectfunnelblueprint.com
www.wash-wear.com
pp-panda74.ru
cevent.net
bellytobabyphotographyseattle.com
alem.be
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
boatshowradio.com
dna-cp.com
acbt.fr
r3.o.lencr.org
wpakademi.com
www.cakav.hu
www.mimid.cz
6chen.cn
goodapd.website
oceanlinen.com
tommarmores.com.br
nesten.dk
zaeba.co.uk
www.n2plus.co.th
koloritplus.ru
h5s.vn
marketisleri.com
www.toflyaviacao.com.br
www.rment.in
www.lagouttedelixir.com
www.krishnagrp.com
big-game-fishing-croatia.hr

How to determine Generic.Ransom.GandCrab4.F98669AC?


File Info:

crc32: 7E0D7F4F
md5: 7b4bb95e555513becd239169d444b9ce
name: 7B4BB95E555513BECD239169D444B9CE.mlw
sha1: dec68a771852bd96393da9dd2de3d3f3604ec009
sha256: 624f844ff28b1eabb78487c5b71fbb880cb6edaf62c6cd0cb716f7e3bcd17ec8
sha512: 613a533b38a5f0b9165e4f11808cc456c0493c93167a88ae6022ecd2dccae6280481fe3629cd1e6b48fb500b8dd04846b594ee750e634a38d2ac3ac79c49831c
ssdeep: 1536:kARw5InSJw/6UM3na7YrlKJfBjB/n0rGpYhqi0sWjcdMIS3FZBq2dks4QTg12A5:9q5dCMXaIIZahhMIS3FZBaCgrQp0Mq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GandCrab4.F98669AC also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d33d1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25859
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGeneric.Ransom.GandCrab4.F98669AC
CylanceUnsafe
SangforWin.Ransomware.Gandcrab-6667060-0
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GandCrab.cc5c9baf
K7GWTrojan ( 0053d33d1 )
Cybereasonmalicious.e55551
CyrenW32/S-02398261!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.GandCrab.D
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Gandcrab-6667060-0
KasperskyTrojan-Ransom.Win32.GandCrypt.fbd
BitDefenderGeneric.Ransom.GandCrab4.F98669AC
NANO-AntivirusTrojan.Win32.GandCrypt.fhmifp
ViRobotTrojan.Win32.GandCrab.131584
MicroWorld-eScanGeneric.Ransom.GandCrab4.F98669AC
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.GandCrab4.F98669AC
SophosMal/Generic-R + Troj/Simda-CF
ComodoTrojWare.Win32.Ransom.GandCrab.D@7uahw7
BitDefenderThetaGen:NN.ZexaF.34050.iuW@aOzaXRii
TrendMicroRansom_GANDCRAB.THHBGAH
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.7b4bb95e555513be
EmsisoftGeneric.Ransom.GandCrab4.F98669AC (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1123427
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27C0283
MicrosoftRansom:Win32/GandCrab.MCTQX
ArcabitGeneric.Ransom.GandCrab4.F98669AC
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.fbd
GDataGeneric.Ransom.GandCrab4.F98669AC
AhnLab-V3Trojan/Win32.Gandcrab.R235161
McAfeeGenericRXAA-AA!7B4BB95E5555
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesRansom.GandCrab
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_GANDCRAB.THHBGAH
RisingRansom.Filecoder!1.B42B (CLASSIC)
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GandCrab.D!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HxQBuFcA

How to remove Generic.Ransom.GandCrab4.F98669AC?

Generic.Ransom.GandCrab4.F98669AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment