Ransom

Ransom.GandCrab.913 (B) removal

Malware Removal

The Ransom.GandCrab.913 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.913 (B) virus can do?

  • Authenticode signature is invalid

How to determine Ransom.GandCrab.913 (B)?


File Info:

name: 5B6BC1F0B63F8D01F9E3.mlw
path: /opt/CAPEv2/storage/binaries/fb1daf13c4239cdeba2e6300d50cdc576c86331216ce2a16d18db0ccac3acaf2
crc32: 4D54BFE3
md5: 5b6bc1f0b63f8d01f9e3d7ab9b7612f0
sha1: a62c388d6d89cafaf275271f561ffe523e1a3465
sha256: fb1daf13c4239cdeba2e6300d50cdc576c86331216ce2a16d18db0ccac3acaf2
sha512: 4dfe15a9058d948c6fb10a7467ac91dff6874546b90016cae9841eaa4647ee2a20bfd2eeb0b7ac63cf4363ce9212481085c08acded6b5ee78f1558dc06ad60e1
ssdeep: 768:Nc0XZN0SPM2fySjZFo7plWoNK6cw3c0vUBY:aCx9fJglWmcmUi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192F36B0275B58477E4A643390CB45B21DABCBC477A38A6C773D8938F2EF20D19A543A3
sha3_384: 8557d721eebe927a88804a75172af97033573fac8b3778552534fa9ab2a4f7bdf01b647559c1bf985061509d8401abb8
ep_bytes: e86a120000e97bfeffff3b0d50301c00
timestamp: 2018-05-07 21:38:10

Version Info:

0: [No Data]

Ransom.GandCrab.913 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GandCrab.913
FireEyeGeneric.mg.5b6bc1f0b63f8d01
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Ransom.GandCrab.913
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Ransom.GandCrab.913
CyrenW32/Kryptik.HKH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GXKS
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win64.CallMeRoot.gen
BitDefenderGen:Variant.Ransom.GandCrab.913
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGen:Variant.Ransom.GandCrab.913
EmsisoftGen:Variant.Ransom.GandCrab.913 (B)
ComodoTrojWare.Win32.Chapak.GO@7o85ni
VIPREGen:Variant.Ransom.GandCrab.913
McAfee-GW-EditionGenericRXGI-RO!5B6BC1F0B63F
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
AviraTR/Crypt.EPACK.Gen2
MicrosoftTrojan:Win32/Meterpreter!ml
GDataGen:Variant.Ransom.GandCrab.913
GoogleDetected
AhnLab-V3Trojan/Win32.Gandcrab.C2499364
McAfeeGenericRXGI-RO!5B6BC1F0B63F
MAXmalware (ai score=89)
MalwarebytesMalware.AI.1878503659
RisingRansom.GandCrab!8.F355 (TFE:5:uaUAWKpdsLC)
YandexTrojan.GenAsa!sEQ6NA0nfs4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GXKS!tr
BitDefenderThetaAI:Packer.922F036A1E
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.0b63f8
PandaTrj/Genetic.gen

How to remove Ransom.GandCrab.913 (B)?

Ransom.GandCrab.913 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment