Malware

How to remove “Mal/Generic-R + Mal/GandCrab-H”?

Malware Removal

The Mal/Generic-R + Mal/GandCrab-H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/GandCrab-H virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Attempts to execute a powershell command with suspicious parameter/s
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Hindi
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Mal/Generic-R + Mal/GandCrab-H?


File Info:

crc32: 9A6B3068
md5: c04c25785b3ba27fa49b0df7fccb8c9e
name: C04C25785B3BA27FA49B0DF7FCCB8C9E.mlw
sha1: 318e61b9e9e3071fca88978fce67aabc1056e46f
sha256: a1f8ed12ea8b480128dae07b18e08af722260cf879145d699ff691b444dbe21f
sha512: fe4fe10e334c9385b8ad7398a107409f8b475917495f3d1d8122f32f5791689ea171959b51e7e9aaf12ccef1b1e319d3e9ecf754af25cb9e221ccc55c2c10d10
ssdeep: 6144:+b/wq/FB3k3GeDDIqaBeTD4byGVAaDM6qM50GRQ7XGJjTWb:+bYkB3k2egqmeAbyGX51RQ65Wb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: drgudbfigbd.isi
FileVersionStart: 1.0.5.4

Mal/Generic-R + Mal/GandCrab-H also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.28004
ClamAVWin.Packed.Generic-9853074-1
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Ransom.Sodinokibi
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Zenpak.3524e26a
K7GWTrojan ( 005563de1 )
K7AntiVirusTrojan ( 005563de1 )
CyrenW32/Kryptik.ABZ.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GVRS
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Zenpak.fwckmh
ViRobotTrojan.Win32.Z.Zenpak.350720
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-R + Mal/GandCrab-H
ComodoTrojWare.Win32.Zenpak.IF@8dwqm4
F-SecureHeuristic.HEUR/AGEN.1107506
BitDefenderThetaGen:NN.ZexaF.34142.vu0@ay7gMuoG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Dropper.fh
FireEyeGeneric.mg.c04c25785b3ba27f
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zenpak.vs
AviraHEUR/AGEN.1107506
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Zenpak
MicrosoftTrojan:Win32/Gandcrab.AF
ArcabitTrojan.Brsecmon.1
SUPERAntiSpywareTrojan.Agent/Gen-GandCrab
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.N
TACHYONRansom/W32.Sodinokibi.350720
AhnLab-V3Win-Trojan/MalPe23.Suspicious.X2005
Acronissuspicious
McAfeeRDN/Generic.grp
VBA32BScope.Trojan.Azorult
MalwarebytesTrojan.BeamWinHTTP
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Kryptik!1.BB49 (CLASSIC)
YandexTrojan.Zenpak!3Kppijo/GNg
IkarusTrojan.Krypt
MaxSecureTrojan.Malware.74505295.susgen
FortinetW32/GenKryptik.DQNE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Mal/Generic-R + Mal/GandCrab-H?

Mal/Generic-R + Mal/GandCrab-H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment