Ransom

About “Ransom.GandCrab.1787” infection

Malware Removal

The Ransom.GandCrab.1787 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.1787 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

Related domains:

lamp.troublerifle.bid
light.representativeglass.bid

How to determine Ransom.GandCrab.1787?


File Info:

crc32: 2F856B8E
md5: 02963179da77bcfd3a5d48482fd304c6
name: 02963179DA77BCFD3A5D48482FD304C6.mlw
sha1: 781f419e9c5efaa5d39b9403a08e88a0091a4aa1
sha256: 4da2631f1f321bb03aa77134f7cb6749d2ccaeb40c672e7ca34b0dd351a45893
sha512: 00a091f83cc111a31558344df163a3791cc8553ea3379668838221c571e0bbb5d384db83a0f55b6db044ec343c1a7ef8af160e51e70ddc2e7a5e5bf2f224ac60
ssdeep: 12288:EaiddeXNvXp1ulxNnlO9wghnQo908X1yBPNiHL:ZiddedvXOxNnlOugJ22
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
Translation: 0x0419 0x04b0

Ransom.GandCrab.1787 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1787
FireEyeGeneric.mg.02963179da77bcfd
CAT-QuickHealSWB.Prepscram.JK6
Qihoo-360Win32/Virus.Adware.b51
McAfeePacked-ZA!02963179DA77
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00528e801 )
BitDefenderGen:Variant.Ransom.GandCrab.1787
K7GWTrojan ( 005267551 )
Cybereasonmalicious.9da77b
BitDefenderThetaGen:NN.ZexaF.34590.pz0@aSKZhHbk
CyrenW32/S-ec8ab2eb!Eldorado
SymantecAdware.IstartSurf
ESET-NOD32a variant of Win32/Kryptik.GCWT
APEXMalicious
AvastFileRepMetagen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
NANO-AntivirusRiskware.Win32.Vittalia.eyyqfr
TencentWin32.Adware.Generic.Eeo
Ad-AwareGen:Variant.Ransom.GandCrab.1787
EmsisoftGen:Variant.Ransom.GandCrab.1787 (B)
ComodoApplication.Win32.IStartSurf.BS@7lng48
F-SecureHeuristic.HEUR/AGEN.1103309
DrWebTrojan.Vittalia.14640
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.mdax
AviraHEUR/AGEN.1103309
Antiy-AVLGrayWare[AdWare]/Win32.AGeneric
MicrosoftSoftwareBundler:Win32/Prepscram
ArcabitTrojan.Ransom.GandCrab.D6FB
SUPERAntiSpywareRansom.GandCrab/Variant
AhnLab-V3PUP/Win32.IStartSurf.R220101
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataGen:Variant.Ransom.GandCrab.1787
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Vittalia
ALYacGen:Variant.Ransom.GandCrab.1787
MAXmalware (ai score=100)
MalwarebytesAdware.IStartSurf
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B032 (CLOUD)
YandexTrojan.GenAsa!FWPhcEJUJ/g
IkarusTrojan.Kryptik
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FXGV!tr
AVGFileRepMetagen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Ransom.GandCrab.1787?

Ransom.GandCrab.1787 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment