Ransom

Ransom.GandCrab.303 removal

Malware Removal

The Ransom.GandCrab.303 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.303 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
bambuko.info
pendosy.site

How to determine Ransom.GandCrab.303?


File Info:

crc32: 7EBE0292
md5: a43e493525619072a9758f47ad9677b5
name: A43E493525619072A9758F47AD9677B5.mlw
sha1: 41972aa8b7291811daecd0137ea2dd942d8e9743
sha256: 4eb2fd0b7efa5a7a01e13192c4333de56c94ef7bd810a18754745d345bf79c8c
sha512: 2665ab82895945595f7f90a0b0b65e733929bc17abd957985babeb4cedfcabd2a7f6f56957c5df88ec8b2952fac2e297c514934cde5eb90adc1412c39d605bf7
ssdeep: 6144:x73TyzSZ5B6vsLKhzWV+xWJYJJJXee6A:x7JRBKhzG+8J9A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0789 0x04b1

Ransom.GandCrab.303 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GandCrab.303
FireEyeGeneric.mg.a43e493525619072
CAT-QuickHealTrojan.Chapak.ZZ6
ALYacGen:Variant.Ransom.GandCrab.303
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1422472
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053305e1 )
BitDefenderGen:Variant.Ransom.GandCrab.303
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.525619
CyrenW32/S-8ce49c37!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packer.Crypter-6539596-1
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.GenKryptik.fbtusq
Ad-AwareGen:Variant.Ransom.GandCrab.303
EmsisoftGen:Variant.Ransom.GandCrab.303 (B)
ComodoTrojWare.Win32.Chapak.GG@7ne4ou
F-SecureHeuristic.HEUR/AGEN.1103318
DrWebTrojan.PWS.Stealer.23758
VIPREBehavesLike.Win32.Malware (v)
TrendMicroRansom_GANDCRAB.SMD3
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-R + Mal/WaledPak-D
IkarusTrojan.Win32.Krypt
JiangminTrojan.PSW.Coins.eg
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1103318
Antiy-AVLTrojan[PSW]/Win32.Coins
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.Ransom.GandCrab.303
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.GandCrab.303
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab01.Exp
Acronissuspicious
McAfeePacked-FFG!A43E49352561
MAXmalware (ai score=96)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GGRG
TrendMicro-HouseCallRansom_GANDCRAB.SMD3
RisingTrojan.Kryptik!1.B1E3 (CLOUD)
YandexTrojan.GenAsa!+YBjRD2hwlk
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.BFJ!tr
BitDefenderThetaGen:NN.ZexaF.34590.pyW@auHLHvfi
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom.GandCrab.303?

Ransom.GandCrab.303 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment