Malware

Mal/GandCrab-G removal

Malware Removal

The Mal/GandCrab-G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Mal/GandCrab-G virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Slovak
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Mal/GandCrab-G?


File Info:

crc32: 1F8F44DD
md5: 39aa9bfcc11e7b886f247294d139cb06
name: starticon7.exe
sha1: f20ef8f3911eb13270abe3aa7605b7d10f7ab719
sha256: e3144bdf5832d4bb313acac8d9f7869995a68ef0bc6818d73d66150eca671655
sha512: 403541297d37e477ac12a8f92d2e66fc05ea4d32e9a048e9a2b00c87bd116c7958149c8880e574e34e07d5f176b8e2dfbf77d75be5020fff31e4ff4ebd47939d
ssdeep: 24576:N8dWm0TWgdjoTOinPWAo/GmcSU0d0KmYD+PaZNtJjkFHf4KDaGCM:NYv0BSii+Ao/Gm9rOKmdPaZNcmSj7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019, ghjhfkh
InternalName: fyukfuyk.exe
FileVersion: 1.0.5.4
ProductVersion: 1.7.6
Translation: 0x0841 0x04c4

Mal/GandCrab-G also known as:

DrWebTrojan.PWS.Stealer.27284
MicroWorld-eScanTrojan.GenericKD.32663389
CAT-QuickHealRansom.Stop.MP4
McAfeeTrojan-FROX!39AA9BFCC11E
CylanceUnsafe
ZillyaTrojan.Stop.Win32.30
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusTrojan ( 0055a9691 )
BitDefenderTrojan.GenericKD.32663389
K7GWTrojan ( 0055a9691 )
Cybereasonmalicious.3911eb
TrendMicroRansom_Stop.R002C0GK119
BitDefenderThetaGen:Trojan.Heur2.PPBB.3.0.lD0@cS7zhvnG7d
F-ProtW32/Kryptik.ANT.gen!Eldorado
SymantecDownloader
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generickdz-7357865-0
GDataTrojan.GenericKD.32663389
KasperskyTrojan-Ransom.Win32.Stop.es
AlibabaRansom:Win32/Stop.408b7909
NANO-AntivirusTrojan.Win32.Stop.gfnogz
RisingTrojan.Kryptik!1.BE9F (CLASSIC)
Ad-AwareTrojan.GenericKD.32663389
SophosMal/GandCrab-G
ComodoMalware@#167jhls2mno72
F-SecureTrojan.TR/AD.InstaBot.cos
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.tm
FireEyeGeneric.mg.39aa9bfcc11e7b88
EmsisoftTrojan.GenericKD.32663389 (B)
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.CTSI-1940
JiangminAdWare.Generic.jyiy
WebrootW32.Trojan.Gen
AviraTR/AD.InstaBot.cos
Antiy-AVLTrojan[Ransom]/Win32.STOP
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F2675D
ZoneAlarmTrojan-Ransom.Win32.Stop.es
MicrosoftRansom:Win32/STOP.BS!MTB
AhnLab-V3Win-Trojan/MalPe26.Suspicious
Acronissuspicious
VBA32TrojanPSW.Stealer
ALYacTrojan.Ransom.Stop
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.GS
PandaGeneric Malware
ESET-NOD32a variant of Win32/Kryptik.GXTR
TrendMicro-HouseCallTrojan.Win32.SMOKELOAD.SMD2.hp
YandexTrojan.Stop!
SentinelOneDFI – Malicious PE
FortinetW32/GenKryptik.DWPH!tr
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Ransom.a3f

How to remove Mal/GandCrab-G?

Mal/GandCrab-G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment