Ransom

Ransom.GandCrab.2689 removal tips

Malware Removal

The Ransom.GandCrab.2689 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.2689 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Ransom.GandCrab.2689?


File Info:

name: A0C37B43FE6F2708F73A.mlw
path: /opt/CAPEv2/storage/binaries/f2ae7536d502e0ca6a93a43515e47e800e305b2763a198d5aab25ca3bef5451a
crc32: 2F595A00
md5: a0c37b43fe6f2708f73a988297a5c2e7
sha1: 91a0a1cffbfbc9728224d23620e435118905142d
sha256: f2ae7536d502e0ca6a93a43515e47e800e305b2763a198d5aab25ca3bef5451a
sha512: a1593de81764958fa5162e71cc490c351be42902bcea172cd0eed6cd31dc5ebd6c9483345c9760944534dbe861752965df6c50a9537d107627b79c30dacc28a1
ssdeep: 49152:KfoOvtpBd4CafaCJrMtvMGPqceTZhTkBjPDFlwyj:6oOVOC4aCBMtvMGP1eTZhABLDFlwy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170A56B01F850A466DB823072ED2DE6396B287E1D87F248F3B6947CD87F751D2313A19A
sha3_384: 8e394aadaba53cea91be4bd98df55587c81a9b74168304b4702b839367c79a548d1796c1cda7c036b1db87b302cc54c1
ep_bytes: 558bec81ec78090000e8e20c00008985
timestamp: 1970-01-01 15:50:05

Version Info:

CompanyName: Opera Software
FileDescription: Opera Browser Assistant Installer
FileVersion: 92.0.4561.21
InternalName: Opera
LegalCopyright: Copyright Opera Software 2022
ProductName: Opera Browser Assistant Installer
ProductVersion: 92.0.4561.21
Translation: 0x0409 0x04b0

Ransom.GandCrab.2689 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Patched.trN0
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GandCrab.2689
FireEyeGeneric.mg.a0c37b43fe6f2708
McAfeeGenericRXIT-BC!A0C37B43FE6F
Cylanceunsafe
VIPREGen:Variant.Ransom.GandCrab.2689
SangforDownloader.Win32.Agent.Vx5j
K7AntiVirusVirus ( 0055485e1 )
AlibabaTrojanDownloader:Win32/SmallAgent.334db0e4
K7GWVirus ( 0055485e1 )
Cybereasonmalicious.3fe6f2
BitDefenderThetaGen:NN.ZexaF.36318.eQ2@a8jdt2ci
VirITWin32.Nov15th.A
CyrenW32/ZeroDloader.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Agent.EQH
ZonerTrojan.Win32.134002
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Patched.rw
BitDefenderGen:Variant.Ransom.GandCrab.2689
AvastWin32:DeadZero [Inf]
EmsisoftGen:Variant.Ransom.GandCrab.2689 (B)
F-SecureMalware.W32/Infector.Gen
DrWebTrojan.DownLoader33.36265
TrendMicroTrojanSpy.Win32.FICKERSTEALER.SMTHA.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosMal/Generic-S
IkarusVirus-Downloader.Win32.Agent
GDataWin32.Trojan.PSE.16VTW2Z
JiangminTrojanDownloader.Generic.bdzi
AviraW32/Infector.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Patched
ArcabitTrojan.Ransom.GandCrab.DA81
ZoneAlarmTrojan.Win32.Patched.rw
MicrosoftTrojanDownloader:Win32/SmallAgent!atmn
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R282625
Acronissuspicious
VBA32BScope.TrojanBanker.CliptoShuffler
ALYacGen:Variant.Ransom.GandCrab.2689
TACHYONWorm/W32.ZeroDownloader
PandaTrj/Chgt.AC
TrendMicro-HouseCallTrojanSpy.Win32.FICKERSTEALER.SMTHA.hp
RisingWorm.Phorpiex!1.BB1C (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.EQH!tr
AVGWin32:DeadZero [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom.GandCrab.2689?

Ransom.GandCrab.2689 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment