Ransom

Ransom.GandCrab.1857 malicious file

Malware Removal

The Ransom.GandCrab.1857 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.1857 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Appends a known encryptJJS ransomware file extension to files that have been encrypted

How to determine Ransom.GandCrab.1857?


File Info:

crc32: 29B18D0A
md5: 942387ef9d9d7b3b81d49d73b55ac9b1
name: 942387EF9D9D7B3B81D49D73B55AC9B1.mlw
sha1: ff7103fee1dc1ecf0b719a995d17825685ffee74
sha256: 9234356069b43bf59ae5e7af7dc28d486975b6735cfabe333cf29e3c7a836cf8
sha512: 59934d15bc95ed3a6b3a17ea9ae02619f87b0fbc4336ae4785220cd08c9b9fb08908d7633ad9196d4467a73a671b5e1dee0829d24cc2669d372b746eea2f8d41
ssdeep: 24576:3gYoUT5CF2veYQ28wrZVg4PNLrUdj0XpTW++or:QYoUT5/eoVV5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) NewSoftwares.net, Inc.
InternalName: UntrustedHealthcare
CompanyName: NewSoftwares.net, Inc.
PrivateBuild: 8.2.6.1
LegalTrademarks: Copyright (c) NewSoftwares.net, Inc.
Comments: Technical Covers
ProductName: UntrustedHealthcare
Languages: English
ProductVersion: 8.2.6.1
FileDescription: Technical Covers
OriginalFilename: UntrustedHealthcare
Translation: 0x0409 0x04b0

Ransom.GandCrab.1857 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26448
CynetMalicious (score: 100)
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.1030
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/GandCrypt.32d06bb2
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f9d9d7
CyrenW32/Ransom.HCOI-0323
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMFA
ZonerTrojan.Win32.73700
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.GandCrypt.fvk
BitDefenderGen:Variant.Ransom.GandCrab.1857
NANO-AntivirusTrojan.Win32.GandCrypt.fisnre
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1857
TencentWin32.Trojan.Gandcrypt.Hqut
Ad-AwareGen:Variant.Ransom.GandCrab.1857
SophosMal/Generic-S
ComodoMalware@#1jhj2p419t7rg
BitDefenderThetaGen:NN.ZexaE.34678.4q0@aeyRgWfi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_GANDCRAB.THJAIAH
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.942387ef9d9d7b3b
EmsisoftGen:Variant.Ransom.GandCrab.1857 (B)
JiangminTrojan.GandCrypt.om
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ransom.GandCrab.D741
AegisLabTrojan.Win32.GandCrypt.4!c
GDataGen:Variant.Ransom.GandCrab.1857
AhnLab-V3Malware/Win32.Ransom_gandcrab.C2790018
McAfeeArtemis!942387EF9D9D
VBA32Trojan.Azden
PandaTrj/CI.A
TrendMicro-HouseCallRansom_GANDCRAB.THJAIAH
RisingRansom.GandCrypt!8.F33E (CLOUD)
YandexTrojan.GandCrypt!o8q4NtsHLLE
IkarusTrojan-Ransom.GandCrab
FortinetW32/GandCrab.761A!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HgIASOoA

How to remove Ransom.GandCrab.1857?

Ransom.GandCrab.1857 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment