Ransom

Generic.Ransom.GarrantDecrypt.B.8F6DAF35 information

Malware Removal

The Generic.Ransom.GarrantDecrypt.B.8F6DAF35 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GarrantDecrypt.B.8F6DAF35 virus can do?

  • Uses Windows APIs to generate a cryptographic key
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Writes a potential ransom message to disk
  • Modifies boot configuration settings
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • CAPE detected the GarrantDecrypt malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Disables Windows firewall
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.GarrantDecrypt.B.8F6DAF35?


File Info:

name: 906C56F0AC8A07A1DC19.mlw
path: /opt/CAPEv2/storage/binaries/e0172d9721bf4532aa30f88808123457b98b40c6865c223e59a16cfbb7350a17
crc32: C08577EB
md5: 906c56f0ac8a07a1dc19df9d28c5d9f4
sha1: 0e7c6c227170492429cf3851cea17195f1985f8b
sha256: e0172d9721bf4532aa30f88808123457b98b40c6865c223e59a16cfbb7350a17
sha512: 51eb3cad7c22185544a4aa9fa9fd2f2551c4cafe072fbd26851befaf5960dfc27f2ed97ef6a146f966c2fd1e4e0c333a8d8a9d3a99da0067882da96aeede25d7
ssdeep: 6144:08pfYeypY+T8Dis6EDppfEZ/TiDcTCMw3IxoV2+43t8cmQOYwOr1UulKGJ+H0JrF:08aeydQnpGZrpM3T4c8POoWPl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C9423772C15CA22D2BD47B67437CA2C0221BF29E99BEE6C81111FDB739E2818C9D50D
sha3_384: 4109ce6f6a84242d46e4c3767653231ffeb4c8e654cadd160c11ea9f68d0485faa3f5b457b6b38904249c048971cd17c
ep_bytes: 558bec81ec180c0000535657ff1558c0
timestamp: 2022-07-02 19:51:04

Version Info:

0: [No Data]

Generic.Ransom.GarrantDecrypt.B.8F6DAF35 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
VIPREGeneric.Ransom.GarrantDecrypt.B.8F6DAF35
SangforTrojan.Win32.Save.a
Cybereasonmalicious.0ac8a0
ESET-NOD32a variant of Win32/Filecoder.Outsider.I
APEXMalicious
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGeneric.Ransom.GarrantDecrypt.B.8F6DAF35
MicroWorld-eScanGeneric.Ransom.GarrantDecrypt.B.8F6DAF35
Ad-AwareGeneric.Ransom.GarrantDecrypt.B.8F6DAF35
SophosMal/Ransom-LX
F-SecureHeuristic.HEUR/AGEN.1234147
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.906c56f0ac8a07a1
EmsisoftGeneric.Ransom.GarrantDecrypt.B.8F6DAF35 (B)
SentinelOneStatic AI – Malicious PE
GDataGeneric.Ransom.GarrantDecrypt.B.8F6DAF35
AviraHEUR/AGEN.1234147
MAXmalware (ai score=85)
ArcabitGeneric.Ransom.GarrantDecrypt.B.8F6DAF35
MicrosoftRansom:Win32/GarrantDecrypt.PA!MTB
AhnLab-V3Trojan/Win.Generic.R413873
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34806.AqW@aijGx5n
ALYacGeneric.Ransom.GarrantDecrypt.B.8F6DAF35
VBA32BScope.TrojanRansom.Agent
RisingRansom.Agent!1.C1EE (CLASSIC)
YandexTrojan.GenAsa!eRWW/cqj0is
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FilecoderProt.F183!tr.ransom
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Generic.Ransom.GarrantDecrypt.B.8F6DAF35?

Generic.Ransom.GarrantDecrypt.B.8F6DAF35 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment