Malware

About “Mal/Generic-S + Mal/GandCrab-H” infection

Malware Removal

The Mal/Generic-S + Mal/GandCrab-H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/GandCrab-H virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-S + Mal/GandCrab-H?


File Info:

crc32: 386D7EF5
md5: 2e29386919ab8d386ba4d73c4a5eb99f
name: 2E29386919AB8D386BA4D73C4A5EB99F.mlw
sha1: 9342d242ea88ee822563678e6b2c75bef3e2cbff
sha256: 74d507670bfc01843eacbfd3d4e14a65bac649f69c5f38d32005ce6127cd494e
sha512: c7564c093f22f8e96a393ebf945da81423eb41daabe45bcce5d577824dcaba66a61783d03475d90029e1bfe52d01e39f3cb7fc0a47039b4c51d931f60888f7fe
ssdeep: 6144:BOyCZcZqYiPlUSCUdj8f3vx/nTE+Dy+KQbBBTsCvUU46iuO:gyCZzYiySCUdG5/TE8KQbz4CsduO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019, mhjhfkh
InternalName: fghfhjkcgyg.exe
ProductVersion: 1.9.6
Translation: 0x0847 0x03fc

Mal/Generic-S + Mal/GandCrab-H also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00555e5a1 )
LionicHacktool.Win32.Nekto.3!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.28813
CynetMalicious (score: 100)
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Ransom.Sodinokibi
CylanceUnsafe
ZillyaExploit.Nekto.Win32.23
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.2eac122c
K7GWTrojan ( 00553c571 )
Cybereasonmalicious.919ab8
ESET-NOD32a variant of Win32/Kryptik.GVAO
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BrsecmonE.1
NANO-AntivirusTrojan.Win32.Propagate.fugwml
MicroWorld-eScanTrojan.BrsecmonE.1
TencentWin32.Trojan.Generic.Hrzd
Ad-AwareTrojan.BrsecmonE.1
SophosMal/Generic-S + Mal/GandCrab-H
ComodoMalware@#edqpjy06x98k
F-SecureTrojan.TR/AD.SodinoRansom.fsm
BitDefenderThetaAI:Packer.AE0F0D1E20
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Trojan.fh
FireEyeGeneric.mg.2e29386919ab8d38
EmsisoftTrojan.BrsecmonE.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.MSIL.aein
AviraTR/AD.SodinoRansom.fsm
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Exploit]/Win32.Nekto
MicrosoftTrojan:Win32/Gandcrab.AF
ArcabitTrojan.BrsecmonE.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BrsecmonE.1
TACHYONTrojan-Exploit/W32.Nekto.349184
AhnLab-V3Win-Trojan/MalPe22.Suspicious.X1995
Acronissuspicious
McAfeeGenericRXIE-EB!2E29386919AB
MAXmalware (ai score=99)
VBA32Malware-Cryptor.Azorult.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Generic@ML.86 (RDMK://HdtetuJ24PrIVeOX/K9w)
IkarusTrojan.Win32.Danabot
FortinetW32/Kryptik.GWIV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Mal/Generic-S + Mal/GandCrab-H?

Mal/Generic-S + Mal/GandCrab-H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment