Malware

Mal/Generic-S + Mal/GandCrab-B malicious file

Malware Removal

The Mal/Generic-S + Mal/GandCrab-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/GandCrab-B virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Estonian
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Mal/Generic-S + Mal/GandCrab-B?


File Info:

crc32: 06475FD5
md5: ec45ef1b554d5f8156843c4a226637a9
name: EC45EF1B554D5F8156843C4A226637A9.mlw
sha1: 20ba2d2a64c3b841f49c49150a04eb7dc724b8a6
sha256: dad54dfec022b59b83d0ab2fcd02874829783c38acba1172a73ed0d529c6d722
sha512: ea08d94e14c3c53c0b97fc3e77ffd8cb0f3ff2371bc84f3cd7ac1ef30716c059d0d64afb2cf9320efe9de3907c0c751bd8c91d0881b575b9871ce406a0b6aa1e
ssdeep: 3072:Tfau2/tyNgs7tm70qiERJT+7nym5aeFCxisejS7NJ+IGfvU6Uj2bJT9hdjCCeI/:f2/BtFbrgCxisTJ+Zu2p9hNCCeI/M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-S + Mal/GandCrab-B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.45344
FireEyeGeneric.mg.ec45ef1b554d5f81
CAT-QuickHealTrojan.Chapak.ZZ6
McAfeeGenericRXGC-SA!EC45EF1B554D
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00543e471 )
BitDefenderTrojan.GenericKDZ.45344
K7GWTrojan ( 0053a0bb1 )
Cybereasonmalicious.b554d5
CyrenW32/S-38342d72!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.38ca4059
NANO-AntivirusTrojan.Win32.Bandit.ffdwjh
ViRobotTrojan.Win32.GandCrab.258048
RisingDownloader.Bandit!8.EDD2 (CLOUD)
Ad-AwareTrojan.GenericKDZ.45344
EmsisoftTrojan.GenericKDZ.45344 (B)
ComodoTrojWare.Win32.Cloxer.FH@7qp6cw
F-SecureHeuristic.HEUR/AGEN.1106533
DrWebTrojan.Encoder.24384
TrendMicroRansom_GANDCRAB.SMALY-3
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S + Mal/GandCrab-B
IkarusTrojan.Win32.Danabot
JiangminTrojan.GandCrypt.gx
AviraHEUR/AGEN.1106533
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Coins
MicrosoftTrojan:Win32/Azorult!ml
ArcabitTrojan.Generic.DB120
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKDZ.45344
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab04.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.muW@aSyN!BfI
ALYacTrojan.GenericKDZ.45344
VBA32TrojanDownloader.Bandit
MalwarebytesMalware.AI.3807626374
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GIRG
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-3
TencentWin32.Trojan.Generic.Alij
YandexTrojan.GenAsa!12KovfPMK4o
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GUKZ!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.PSW.f95

How to remove Mal/Generic-S + Mal/GandCrab-B?

Mal/Generic-S + Mal/GandCrab-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment