Ransom

How to remove “Ransom:Win32/GandCrab.AC”?

Malware Removal

The Ransom:Win32/GandCrab.AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GandCrab.AC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.corp-servers.ru
zonealarm.bit
ns2.corp-servers.ru

How to determine Ransom:Win32/GandCrab.AC?


File Info:

crc32: 7929B757
md5: 5d897922efbd6496760d933e58af7f04
name: 5d897922efbd6496760d933e58af7f04.exe
sha1: 277769be453c485b7d6c7e2b7eec81103bcf14b6
sha256: 91239321d3acabf9b4c2911ab2dcbd9c83f0695fb94980d2072d54bbb09ca935
sha512: 72c9cbd13ddd41fbee7479a9ec61e91389201da574c8112033cf4d3a50cd5dd2923b07074401c865fa18c5a022856a5189c17e8293341af821a0887e8af936da
ssdeep: 6144:JD1MW6R8c9u9UriRV3tJgkp7E9sXdVyyg6:vM7R8Kor17fdpg6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/GandCrab.AC also known as:

MicroWorld-eScanTrojan.GenericKDZ.43669
FireEyeGeneric.mg.5d897922efbd6496
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXFA-GU!5D897922EFBD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.43669
K7GWTrojan ( 0052ed291 )
K7AntiVirusTrojan ( 0052ed291 )
TrendMicroRansom_HPGANDCRAB.SMG
F-ProtW32/S-0040c436!Eldorado
SymantecPacked.Generic.525
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packer.Crypter-6539596-1
GDataTrojan.GenericKDZ.43669
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/GandCrab.895bd0ad
NANO-AntivirusTrojan.Win32.Encoder.faneec
ViRobotTrojan.Win32.GandCrab.Gen.A
RisingRansom.GandCrab!1.BC54 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.43669
SophosMal/Agent-AUL
ComodoTrojWare.Win32.Ransom.Crusis.A@7me98z
F-SecureTrojan.TR/GandCrab.tvnwt
DrWebTrojan.Encoder.24384
ZillyaTrojan.GandCrypt.Win32.151
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.43669 (B)
IkarusTrojan-Ransom.GandCrab
CyrenW32/S-0040c436!Eldorado
JiangminTrojan.Chapak.gz
WebrootTrojan.Dropper.Gen
AviraTR/GandCrab.tvnwt
MAXmalware (ai score=81)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.DAA95
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRansom:Win32/GandCrab.AC
AhnLab-V3Win-Trojan/Gandcrab02.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.32515.puX@aiNu2fo
ALYacTrojan.GenericKDZ.43669
VBA32BScope.Trojan.Chapak
PandaTrj/Genetic.gen
ZonerTrojan.Win32.68397
ESET-NOD32Win32/Filecoder.GandCrab.B
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG
YandexTrojan.GandCrypt!
SentinelOneDFI – Malicious PE
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GWXD!tr
AVGWin32:Malware-gen
Cybereasonmalicious.2efbd6
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM10.2.2305.Malware.Gen

How to remove Ransom:Win32/GandCrab.AC?

Ransom:Win32/GandCrab.AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment