Ransom

Ransom.GandCrab.1967 removal tips

Malware Removal

The Ransom.GandCrab.1967 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.1967 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.GandCrab.1967?


File Info:

crc32: 03ECCADC
md5: 4a389be5212de4e490cb1788a77d3c91
name: 4A389BE5212DE4E490CB1788A77D3C91.mlw
sha1: af7a90d7dc6336fd8a3ee156cc97de94729ababa
sha256: 48ef660a7d9b25c3283559d54950358484fad30ebc97fe8d1a9225c88cd3de20
sha512: 920a6d60c6c96739e77f7e21249ea1ee6e70a0f3d46de8a7541e88bc18fccb71bc0dab7aee4bd0b426f67df69e2281454681e2534a2c3764cafdec0c4d411e76
ssdeep: 12288:27l49/fLuRbjqInQ6BBENs0riDIPixmLVWZ9T:27G/fLuRXBxvENmIqxmZ49
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.GandCrab.1967 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053fb461 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.41379
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.GandCrab.1967
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1002507
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaVirTool:Win32/CeeInject.5c9530aa
K7GWTrojan ( 0053fb461 )
Cybereasonmalicious.5212de
SymantecTrojan.Gen.2
ESET-NOD32Win32/TrojanDownloader.Carberp.CD
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.GandCrab.1967
NANO-AntivirusTrojan.Win32.Packed2.fjokjg
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1967
TencentMalware.Win32.Gencirc.10ccbc42
Ad-AwareGen:Variant.Ransom.GandCrab.1967
SophosMal/Generic-R + Mal/Kryptik-CY
ComodoMalware@#nmwclq6r92bb
BitDefenderThetaGen:NN.ZexaF.34692.ivZ@aGaMb@ji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericR-OXI!4A389BE5212D
FireEyeGeneric.mg.4a389be5212de4e4
EmsisoftGen:Variant.Ransom.GandCrab.1967 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agent.bqxz
AviraTR/AD.Carberp.apilr
Antiy-AVLTrojan/Generic.ASMalwS.28C4E67
MicrosoftVirTool:Win32/CeeInject.BDE!bit
ArcabitTrojan.Ransom.GandCrab.D7AF
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.GandCrab.1967
McAfeeGenericR-OXI!4A389BE5212D
MAXmalware (ai score=88)
PandaTrj/GdSda.A
RisingRansom.GandCrab!8.F355 (CLOUD)
YandexTrojan.GenAsa!6eSKyKul7Pc
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.CKDY!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.GandCrab.1967?

Ransom.GandCrab.1967 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment