Ransom

Ransom:Win32/GandCrab.AO information

Malware Removal

The Ransom:Win32/GandCrab.AO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GandCrab.AO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.virmach.ru
politiaromana.bit
malwarehunterteam.bit
ns2.virmach.ru
gdcb.bit

How to determine Ransom:Win32/GandCrab.AO?


File Info:

crc32: 92585E56
md5: 4f09d4bbc4ac9767afc022316b039257
name: 4F09D4BBC4AC9767AFC022316B039257.mlw
sha1: bd5680d36822a1e7407b401d52b20869c98a3008
sha256: 4e9de489452c9eb4b9f5810140e45eecadaacc396c869a13787ce474cb45cae5
sha512: 6b4b9d6b26f09d15445820022995968fb9e6c12d03e03dd7e7281febf04fdd88ca89d2369ea8cb427414094c1f775014a748774dad12aaea7b62f2600a5a8a48
ssdeep: 6144:6f7Q4jqxi1HL8xm1e4lcEtM7appYNADniVSp+IZb:+pjqxip1R1tBESDniVSp+IZb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/GandCrab.AO also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.4f09d4bbc4ac9767
CAT-QuickHealTrojan.Chapak.A03
ALYacTrojan.Ransom.GandCrab.Gen.2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agentb.4!c
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 003e58dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34590.quX@aGsrR2mi
CyrenW32/S-9eec4df2!Eldorado
SymantecRansom.GandCrab
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Gandcrab-6552923-4
KasperskyHEUR:Trojan-Ransom.Win32.GandCrypt.gen
AlibabaRansom:Win32/GandCrab.ali1020003
NANO-AntivirusTrojan.Win32.Chapak.eyroie
ViRobotTrojan.Win32.GandCrab.Gen.A
TencentMalware.Win32.Gencirc.10b49214
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
ComodoTrojWare.Win32.Magniber.A@7k48mn
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Agentb.Win32.19061
TrendMicroRansom_GANDCRAB.SMALY-2
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-R + Mal/Agent-AUL
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.Agent.bfll
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Agentb
MicrosoftRansom:Win32/GandCrab.AO
ArcabitTrojan.Ransom.GandCrab.Gen.2
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan-Ransom.Win32.GandCrypt.gen
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
McAfeePacked-FBN!4F09D4BBC4AC
MAXmalware (ai score=99)
VBA32Downloader.Snojan
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GDZP
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-2
RisingRansom.GandCrab!1.BD8C (CLOUD)
YandexTrojan.GenAsa!OXZ47WtMnVw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/GenKryptik.DWPH!tr
AVGWin32:Malware-gen
Cybereasonmalicious.bc4ac9
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCc5gA

How to remove Ransom:Win32/GandCrab.AO?

Ransom:Win32/GandCrab.AO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment