Ransom

Generic.Ransom.GandCrab4.FEA8E5C9 removal guide

Malware Removal

The Generic.Ransom.GandCrab4.FEA8E5C9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GandCrab4.FEA8E5C9 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Generic.Ransom.GandCrab4.FEA8E5C9?


File Info:

crc32: BFF479A1
md5: ef50f5c2d6d8d10d8adc1efb840518d0
name: EF50F5C2D6D8D10D8ADC1EFB840518D0.mlw
sha1: 455530470a9496110a158229d6e09094dba28bcf
sha256: 8bd9ca75496baa5fcc5a39995e7c8f8c84a73dc56122d67fbf2bc9ea1c53c2e1
sha512: 50e2afc78bb86be91b63fcd20150c9f844893aa99424518f2016c5d19c33c091061b48d5219d18fb04f41cad4a8ba4eb7e6fce47cdf8174f4566eebbe4344374
ssdeep: 1536:SHNMcdzJWZ/lw2DD8fZRrgwOCMCiWl+/V2VswsWjcdZr2lIhATK2dks4QTg12A5:yMc/n28fDrVONk6Z2IhAT6CgrQp0MX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GandCrab4.FEA8E5C9 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d33d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
ClamAVWin.Ransomware.Gandcrab-6614714-0
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.GandCrab
MalwarebytesRansom.GandCrab
ZillyaTrojan.Generic.Win32.109697
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Any/UnSafe.a
K7GWTrojan ( 0053d33d1 )
Cybereasonmalicious.2d6d8d
CyrenW32/Gandcrab.O.gen!Eldorado
SymantecRansom.GandCrab!g4
ESET-NOD32a variant of Win32/Filecoder.GandCrab.D
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.GandCrab4.FEA8E5C9
NANO-AntivirusTrojan.Win32.Encoder.fexjgn
MicroWorld-eScanGeneric.Ransom.GandCrab4.FEA8E5C9
TencentMalware.Win32.Gencirc.10c8fe21
Ad-AwareGeneric.Ransom.GandCrab4.FEA8E5C9
SophosMal/Generic-S + Troj/GandCrab-Q
ComodoTrojWare.Win32.Ransom.GandCrab.D@7uahw7
BitDefenderThetaGen:NN.ZexaF.34670.huW@aewLvLji
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_GANDCRAB.THGAAAH
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.ef50f5c2d6d8d10d
EmsisoftGeneric.Ransom.GandCrab4.FEA8E5C9 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cjlhw
WebrootW32.Trojan.Gen
AviraTR/AD.GandCrab.zfxje
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/GandCrab.AP
GDataGeneric.Ransom.GandCrab4.FEA8E5C9
TACHYONRansom/W32.GandCrab.124416.D
AhnLab-V3Trojan/Win32.Gandcrab.R231444
Acronissuspicious
McAfeeRan-GandCrabv4!EF50F5C2D6D8
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.GandCrypt
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_GANDCRAB.THGAAAH
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.GenAsa!4tjTq6hhNDE
IkarusTrojan-Ransom.GandCrab
FortinetW32/GandCrab.D!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HxQBwnEA

How to remove Generic.Ransom.GandCrab4.FEA8E5C9?

Generic.Ransom.GandCrab4.FEA8E5C9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment