Ransom

How to remove “Generic.Ransom.GoldenEye.5F680005”?

Malware Removal

The Generic.Ransom.GoldenEye.5F680005 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GoldenEye.5F680005 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Executed a sysinternals tool
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the Petya malware family
  • Attempted to write directly to a physical drive
  • Clears Windows events or logs
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Created a service that was not started
  • PSExec was executed
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Ransom.GoldenEye.5F680005?


File Info:

name: 849E7046320A7E770C08.mlw
path: /opt/CAPEv2/storage/binaries/645f245f81833e9140731577a4efed89650e2e3f1b3319f79931a505b89378d4
crc32: 853D7F39
md5: 849e7046320a7e770c08815cc59c8c75
sha1: 9b53fc9217dc823da0a5a790aa8cbd79ee5a1d4b
sha256: 645f245f81833e9140731577a4efed89650e2e3f1b3319f79931a505b89378d4
sha512: 94cc2e9db84e03a4aabf0031666f393e342736f1c3d39a9715b76498d11282c81009bf0b392f26b91eb89047ecf149f12dbb38a635c44241d496e15a8443db98
ssdeep: 6144:ie3j9m7igs7YpjpFRedx0b7BMVoei7NsOn9S4ZLNhEJqX4hi2kJTMfZzVWuXXC7P:iC9tgs76wdxMdeksOn9lRDEJC4I3JTMg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6742296995FC8C2F9908D3471A5F8E8E2A8B0E30B54B4E54D37EB96C4317B7A30D847
sha3_384: f1d1787299a867a60081e7012bd02ad98aca10fa22f2e2bc4e7f1f6c2dd5562768e36eb1156798b836e5b9d7563594c3
ep_bytes: 60be000041008dbe0010ffff5783cdff
timestamp: 2019-07-08 10:54:36

Version Info:

0: [No Data]

Generic.Ransom.GoldenEye.5F680005 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Petr.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGeneric.Ransom.GoldenEye.5F680005
ClamAVWin.Exploit.CVE_2017_0147-6331310-0
FireEyeGeneric.mg.849e7046320a7e77
CAT-QuickHealRansom.Petya.A5
ALYacTrojan.Ransom.Petya
Cylanceunsafe
VIPREGeneric.Ransom.GoldenEye.5F680005
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0051156f1 )
AlibabaRansom:Win32/Petya.eadad299
K7GWTrojan ( 0051156f1 )
CrowdStrikewin/malicious_confidence_60% (D)
BaiduWin32.Trojan.Ransom.a
SymantecRansom.Petya
ESET-NOD32Win32/Diskcoder.C
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Petr.xw
BitDefenderGeneric.Ransom.GoldenEye.5F680005
NANO-AntivirusTrojan.Win32.Petya.eqlcgp
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.FalseSign.Qgil
SophosMal/Generic-R
F-SecureTrojan.TR/Ransom.ME.12
DrWebTrojan.Encoder.28827
ZillyaTrojan.Petr.Win32.78
McAfee-GW-EditionGenericRXHW-OW!EF3FA361CE60
Trapminesuspicious.low.ml.score
EmsisoftGeneric.Ransom.GoldenEye.5F680005 (B)
IkarusTrojan-Ransom.Petrwrap
GDataGeneric.Ransom.GoldenEye.5F680005
JiangminTrojan.Petr.au
AviraTR/Ransom.ME.12
Antiy-AVLTrojan[Ransom]/Win64.ExPetya
ArcabitGeneric.Ransom.GoldenEye.5F680005
ZoneAlarmTrojan-Ransom.Win32.Petr.xw
MicrosoftRansom:Win32/Petya.B!rsm
GoogleDetected
AhnLab-V3Trojan/Win32.Diskcoder.C3329390
McAfeeArtemis!849E7046320A
MAXmalware (ai score=100)
VBA32Trojan.Ransom.Filecoder
MalwarebytesMalware.Heuristic.1003
PandaTrj/GdSda.A
RisingRansom.Petya!1.ABCF (CLOUD)
YandexTrojan.Petr!OHbydvjYCJQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11095467.susgen
FortinetW32/Petya.C!tr.ransom
BitDefenderThetaGen:NN.ZexaF.36250.vmHfaqp5x9ei
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Generic.Ransom.GoldenEye.5F680005?

Generic.Ransom.GoldenEye.5F680005 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment