Ransom

What is “Ransom.GandCrab.1870 (B)”?

Malware Removal

The Ransom.GandCrab.1870 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.1870 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Faeroese
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Ransom.GandCrab.1870 (B)?


File Info:

crc32: 5A3C1ADF
md5: 44a6fd81b0465f7b4363e9524d7cb990
name: 44A6FD81B0465F7B4363E9524D7CB990.mlw
sha1: 4d596fb363f3f782b88efac35dcad42ed07c038e
sha256: adb7c5b002effd80f4cabf6f5b8ca81ed72b8e3bed97f8bed06b9916ffc505b1
sha512: 46a8339d4c31e02d060e828bf9066b252d1b0a3c1abb4a675f30a6eb6dc95c59e373f28e53480b05162b34d5a122fb76e2f20aba67fcb530c7f21eb487601c08
ssdeep: 6144:6wrj8OsuuKtFjmfzJAOAq/sYVWPqjYoMlz:6wrgBsGzJh/sYuqvQz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 8.4.3.12

Ransom.GandCrab.1870 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d5971 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.GandCrab.1870
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanPSW:Win32/Coins.26975d69
K7GWTrojan ( 0053d5971 )
Cybereasonmalicious.1b0465
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GJUD
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan-PSW.Win32.Coins.gux
BitDefenderGen:Variant.Ransom.GandCrab.1870
NANO-AntivirusTrojan.Win32.Coins.fhowwg
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1870
TencentWin32.Trojan-qqpass.Qqrob.Pdco
Ad-AwareGen:Variant.Ransom.GandCrab.1870
SophosML/PE-A + Mal/GandCrab-B
ComodoTrojWare.Win32.Ransom.Gandcrab.GJ@7tcda3
BitDefenderThetaGen:NN.ZexaF.34758.pu0@aOe9IxiG
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.44a6fd81b0465f7b
EmsisoftGen:Variant.Ransom.GandCrab.1870 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Coins.hu
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1103366
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.280557C
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Ransom.GandCrab.1870
AhnLab-V3Win-Trojan/Gandcrab07.Exp
Acronissuspicious
McAfeePacked-FKN!44A6FD81B046
MAXmalware (ai score=100)
VBA32TrojanPSW.Coins
MalwarebytesMalware.AI.1536799680
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!UPNmkLxTbVE
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.GJUV!tr.ransom
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Ransom.GandCrab.1870 (B)?

Ransom.GandCrab.1870 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment