Malware

Mal/GandCrab-C removal tips

Malware Removal

The Mal/GandCrab-C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/GandCrab-C virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Mal/GandCrab-C?


File Info:

name: 093E05C4A99A60557880.mlw
path: /opt/CAPEv2/storage/binaries/757191010d0108303aeb051812e88458d9f0bb8fbde2129d1af2b5c3afcad3cd
crc32: 6AB6D28A
md5: 093e05c4a99a6055788034fceb732156
sha1: 9cdcb41e144a645f9a1da3a6138d0cbfaad32e0f
sha256: 757191010d0108303aeb051812e88458d9f0bb8fbde2129d1af2b5c3afcad3cd
sha512: 85d2ce4ded77546416f770580543cfc7ad809da88fd0350ff7fb869b313b3461873e3498affe407d30226a5fd30edb8ddc65b05bf0c67aa7603358bc134dd233
ssdeep: 3072:XWQcJFTJ7+nMTHEd/E3IDmfOJ9HlH6GxPm5EwXfh6Hl:mZZCniHEltmm7N6Gx+5EwXfh6F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6F39D509948D221DE148A344E7EE35A0EF9FA279DBD4D876680A8FD2D13D52F432B33
sha3_384: fdb313671c737c80169fd6387afe059c34bde0e12a9e57a4f8a0f57a12f76df7e932ea4a938a59c0d090395da22c36e2
ep_bytes: e8d9130000e989feffff8bff558bec8b
timestamp: 2018-03-25 05:06:21

Version Info:

FileVersion: 1.0.3.2
InternalName: sgahffjfghj.exe
LegalCopyright: Copyright (C) 2017, zesdatoo
ProductVersion: 1.0.3.2
Translation: 0x0809 0x04b0

Mal/GandCrab-C also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Chapak.tpom
MicroWorld-eScanTrojan.Agent.DRPZ
CAT-QuickHealTjnRansom.GandCrab.S2235386
McAfeeGenericRXFZ-UV!093E05C4A99A
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Chapak.Win32.1614
SangforRansom.Win32.Gandcrab_18.se2
K7AntiVirusTrojan ( 0052b8321 )
AlibabaRansom:Win32/Gandcrab.54a
K7GWTrojan ( 0052b8321 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Encoder.BKBW
CyrenW32/S-06a2b15e!Eldorado
SymantecPacked.Generic.620
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Packed.Gandcrab-6552923-4
BitDefenderTrojan.Agent.DRPZ
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
TencentTrojan-Ransom.Win32.Gandcrypt.d
EmsisoftTrojan.Agent.DRPZ (B)
F-SecureTrojan.TR/Crypt.XPACK.bilyo
DrWebTrojan.Encoder.24384
VIPRETrojan.Agent.DRPZ
TrendMicroTSPY_EMOTET.SMB1
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeTrojan.Agent.DRPZ
SophosMal/GandCrab-C
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.DRPZ
JiangminTrojan.Chapak.bv
GoogleDetected
AviraTR/Crypt.XPACK.bilyo
MAXmalware (ai score=81)
Antiy-AVLTrojan[Banker]/Win32.Jimmy
XcitiumTrojWare.Win32.Chapak.EV@7loiva
ArcabitTrojan.Agent.DRPZ
ViRobotTrojan.Win32.GandCrab.Gen.A
MicrosoftRansom:Win32/GandCrab.E
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RansomCrypt.C2442870
ALYacTrojan.Agent.DRPZ
TACHYONRansom/W32.GandCrab
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_EMOTET.SMB1
RisingTrojan.Kryptik!1.C8F4 (CLASSIC)
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Ransom.GandCrab.Gen
FortinetW32/Agent.DRPZ!tr
Cybereasonmalicious.4a99a6
DeepInstinctMALICIOUS

How to remove Mal/GandCrab-C?

Mal/GandCrab-C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment