Ransom

Ransom.GandCrab.1903 removal

Malware Removal

The Ransom.GandCrab.1903 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.1903 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Czech
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

How to determine Ransom.GandCrab.1903?


File Info:

crc32: 64B9E376
md5: 7aae7b40ed97c8054dc6b97b74b897dc
name: 7AAE7B40ED97C8054DC6B97B74B897DC.mlw
sha1: e7233f4f2c4f716fefd2945d642510d6876eb53c
sha256: 7d0093ba25a32b1619f23a865ed813c37cbebcbc566cf6336d2ec85e262c643f
sha512: e0353bd4068849cc2cb35d3abdfd65055481e61b7edb6c58c401b7280ec00ca0c998775acf7136a30238432857cd43a96f54b6773f02d4aae85b4cd655980419
ssdeep: 3072:86PzlWMGQC2mCeKpXQ46mDO7gaPvz5Qr+pUwdKIfz6D2tjBA6NyXP96w8R/:86PzggxQ41DQgaHzSEd7fz6Ajwf96w
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sgfnghmj.exe
FileVersion: 8.4.3.12

Ransom.GandCrab.1903 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d5971 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.56435
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.GandCrab.1903
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 0053d5971 )
Cybereasonmalicious.0ed97c
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GJRD
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Chapak.anoi
BitDefenderGen:Variant.Ransom.GandCrab.1903
NANO-AntivirusTrojan.Win32.Kryptik.fgphun
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1903
TencentWin32.Trojan.Chapak.Akfu
Ad-AwareGen:Variant.Ransom.GandCrab.1903
SophosMal/Generic-S + Mal/GandCrab-G
ComodoMalware@#ewksp1cti9k1
BitDefenderThetaGen:NN.ZexaF.34608.nu0@ayv6sEaG
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.7aae7b40ed97c805
EmsisoftGen:Variant.Ransom.GandCrab.1903 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1103322
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/GandCrab.AT!bit
AegisLabTrojan.Win32.Chapak.4!c
GDataGen:Variant.Ransom.GandCrab.1903
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeePacked-FKN!7AAE7B40ED97
MAXmalware (ai score=100)
VBA32Trojan.Chapak
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
IkarusTrojan-Downloader.Win32.Zurgop
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GKJF!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.333

How to remove Ransom.GandCrab.1903?

Ransom.GandCrab.1903 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment