Ransom

How to remove “Ransom.GandCrab.1930 (B)”?

Malware Removal

The Ransom.GandCrab.1930 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.1930 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Slovenian
  • The binary likely contains encrypted or compressed data.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Ransom.GandCrab.1930 (B)?


File Info:

crc32: 567D4FCA
md5: 9645a10b2eef4e9c0bb85db8b91b968d
name: 9645A10B2EEF4E9C0BB85DB8B91B968D.mlw
sha1: f63dcc4a31f6afab07b34348ec6d193b23f46b3a
sha256: 8f8d426a38c2702f285fee9f086c144e352c2ae1277adae745d82c027bc988db
sha512: c5e267acdd8aef54a121d1f772ade5d6baab4af84f7769185c5327dfdaca1546ae3ea0df10329875552ab085b22affc13d93875907317d35189302bedf2aa39d
ssdeep: 3072:NvHL52pca5CeTGRHmeXpJM/nhpXSwaHVUDmuz5:lHLY5eXpuJpXTaHqH1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.GandCrab.1930 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24300
CynetMalicious (score: 100)
CAT-QuickHealWorm.Gamarue.MUE.ZZ4
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.e08dcb35
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.b2eef4
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GJOF
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Ransomware.Gandcrab-7340174-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.GandCrab.1930
NANO-AntivirusTrojan.Win32.Coins.fifpbz
ViRobotTrojan.Win32.R.Agent.171008.F
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1930
TencentWin32.Trojan.Generic.Hsif
Ad-AwareGen:Variant.Ransom.GandCrab.1930
SophosML/PE-A + Mal/GandCrab-G
ComodoTrojWare.Win32.PSW.Coins.FS@7s47lc
BitDefenderThetaGen:NN.ZexaF.34678.kuW@aG4vG6ic
TrendMicroRansom_GANDCRAB.SMALY-3
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.9645a10b2eef4e9c
EmsisoftGen:Variant.Ransom.GandCrab.1930 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Chapak.my
WebrootW32.Adware.Installcore
AviraTR/GandCrab.idl
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Predator!ml
AegisLabTrojan.Win32.GandCrypt.trvc
GDataGen:Variant.Ransom.GandCrab.1930
AhnLab-V3Win-Trojan/Gandcrab04.Exp
Acronissuspicious
McAfeePacked-FJN!9645A10B2EEF
MAXmalware (ai score=100)
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-3
RisingRansom.GandCrypt!8.F33E (CLOUD)
YandexTrojan.GenAsa!K231r3FxgKE
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HCUD!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Ransom.GandCrab.1930 (B)?

Ransom.GandCrab.1930 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment