Malware

Mal/Generic-S + Mal/GandCrypt-B (file analysis)

Malware Removal

The Mal/Generic-S + Mal/GandCrypt-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/GandCrypt-B virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Faeroese
  • The binary likely contains encrypted or compressed data.

Related domains:

telete.in

How to determine Mal/Generic-S + Mal/GandCrypt-B?


File Info:

crc32: 25059DAC
md5: 20223c62801c7b6891949ec051ced31a
name: 20223C62801C7B6891949EC051CED31A.mlw
sha1: 1474a4de34024262b067dcc2df80281a324b1253
sha256: 76930d2d4c02e546387cc19858c9dcb720d84f43ed845b619d7c0900b18c9740
sha512: 040c6aadb572f8b6357e853eee940644cfddbc6b1a56e76b3522ec1bbb39b78151cacb9e55cdb055c64702520042a4f4e9d892d0973220792ecae5994ab897cb
ssdeep: 12288:JK3bMbnDa1XsxH1XQhoyGsn10qjdTr0jV7s2XZO+MKB7rt41jHtNVXsL:kMbDmg1XTyDW5s2XZOAHt2hXsL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersus: 1.0.85.28
ProductVersus: 1.0.85.28
Translations: 0x0185 0x00fa

Mal/Generic-S + Mal/GandCrypt-B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop17.37912
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.22035d7b
K7GWTrojan ( 0057cd661 )
Cybereasonmalicious.e34024
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKZM
APEXMalicious
AvastWin32:BotX-gen [Trj]
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKD.36940249
MicroWorld-eScanTrojan.GenericKD.36940249
Ad-AwareTrojan.GenericKD.36940249
SophosMal/Generic-S + Mal/GandCrypt-B
Comodo.UnclassifiedMalware@0
BitDefenderThetaGen:NN.ZexaF.34690.LuW@a0RTKHlG
McAfee-GW-EditionBehavesLike.Win32.Lockbit.hc
FireEyeGeneric.mg.20223c62801c7b68
EmsisoftTrojan.GenericKD.36940249 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.B!rfn
AegisLabTrojan.Win32.Stop.j!c
GDataTrojan.GenericKD.36940249
AhnLab-V3Trojan/Win.Glupteba.R422001
Acronissuspicious
McAfeeArtemis!20223C62801C
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CEL21
RisingRansom.Stop!8.10810 (CLOUD)
IkarusTrojan.Win32.FakeAV
FortinetW32/Kryptik.HKZH!tr
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml

How to remove Mal/Generic-S + Mal/GandCrypt-B?

Mal/Generic-S + Mal/GandCrypt-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment