Ransom

Ransom:Win32/GandCrab.AT!bit removal instruction

Malware Removal

The Ransom:Win32/GandCrab.AT!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GandCrab.AT!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Czech
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.billerimpex.com
www.macartegrise.eu
www.poketeg.com
perovaphoto.ru
asl-company.ru
www.fabbfoundation.gm
www.perfectfunnelblueprint.com
www.wash-wear.com
pp-panda74.ru
cevent.net
bellytobabyphotographyseattle.com
alem.be
apps.identrust.com
crl.identrust.com
boatshowradio.com
dna-cp.com
acbt.fr
r3.o.lencr.org
wpakademi.com
www.cakav.hu
www.mimid.cz
6chen.cn
goodapd.website
oceanlinen.com
tommarmores.com.br
nesten.dk
zaeba.co.uk
www.n2plus.co.th
koloritplus.ru
h5s.vn
edgedl.gvt1.com

How to determine Ransom:Win32/GandCrab.AT!bit?


File Info:

crc32: 3AFA4062
md5: 50001008c2fc53e78bb8985d63ddf724
name: 50001008C2FC53E78BB8985D63DDF724.mlw
sha1: 0d9fbb8698042e40f5566f357a7bf61685a87a9b
sha256: 4f64ae47f03a0440bcfb75adb8571d64da29a2e51b477f19bf38e135b48e0224
sha512: 4bde1cef14a7da6be5b7a8fca98bc0cb55f53b248545193487a0c21f34832c3822cd9060d130be2410c50566faef3bef2ae20d4525de63f7ec13e7c2dd3d5e3c
ssdeep: 3072:Y6PzleVQC2mCekpX8lAC7p7gjz2uH1+pUzuKpF+jPJ90c4jaJo8SITu9WNfXP96:Y6Pz7x8lz7Vgj6YZum0/i8vTumf96w
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sgfnghmj.exe
FileVersion: 8.4.3.12

Ransom:Win32/GandCrab.AT!bit also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25810
MicroWorld-eScanGen:Variant.Ransom.GandCrab.1903
FireEyeGeneric.mg.50001008c2fc53e7
Qihoo-360Win32/Trojan.8af
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
AegisLabTrojan.Win32.GandCrypt.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053d5971 )
BitDefenderGen:Variant.Ransom.GandCrab.1903
K7GWTrojan ( 0053d5971 )
Cybereasonmalicious.8c2fc5
BitDefenderThetaAI:Packer.F499261020
SymantecPacked.Generic.525
TrendMicro-HouseCallMal_HPGen-50
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/GandCrab.df667cd4
NANO-AntivirusTrojan.Win32.GandCrypt.fifowk
ViRobotTrojan.Win32.R.Agent.273408.E
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
Ad-AwareGen:Variant.Ransom.GandCrab.1903
SophosMal/Generic-S + Mal/GandCrab-G
ComodoMalware@#32n7eek5pnor2
F-SecureHeuristic.HEUR/AGEN.1103366
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Variant.Ransom.GandCrab.1903 (B)
IkarusTrojan-Downloader.Win32.Zurgop
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1103366
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt
MicrosoftRansom:Win32/GandCrab.AT!bit
ArcabitTrojan.Ransom.GandCrab.D76F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.GandCrab.1903
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeePacked-FKN!50001008C2FC
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.GJRD
TencentWin32.Trojan.Generic.Sqtc
YandexTrojan.GenAsa!DJKV6anhAB4
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GKJF!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureRansomeware.CRAB.gen

How to remove Ransom:Win32/GandCrab.AT!bit?

Ransom:Win32/GandCrab.AT!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment