Ransom

How to remove “Ransom:Win32/GandCrab.E”?

Malware Removal

The Ransom:Win32/GandCrab.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GandCrab.E virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.bit
emsisoft.bit
gandcrab.bit

How to determine Ransom:Win32/GandCrab.E?


File Info:

crc32: 9B7BF344
md5: 88ef2f11ff365e448b6900a5ba2fffa0
name: 88EF2F11FF365E448B6900A5BA2FFFA0.mlw
sha1: 02858d7566f8324ac6eeb6e4b9a0867bf555b8a4
sha256: 0d641a6e15a1b393fa49c6c2e98ada6e7a04a9163667f667d3776786515d0991
sha512: 906457d40771a063e4e9c977760c946821cf20260b301110755999e046fa09d7255f00c3973abcca0c07fb1b5f74a3e0735d0a116773bb7997d7578736d7d0db
ssdeep: 1536:8gSeGDjtQhnwmmB0yjMqqUM2mr3IdE8mne0Avu5r++yy7CA7GcIaapavdv:8MSjOnrmBbMqqMmr3IdE8we0Avu5r++
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/GandCrab.E also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.GandCrab.1DA8B53A
FireEyeGeneric.mg.88ef2f11ff365e44
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Win32/Trojan.Ransom.GandCrab.F
McAfeeGenericRXDY-EJ!88EF2F11FF36
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.GandCrypt.tqLj
SangforWin.Ransomware.Gandcrab-6667060-0
K7AntiVirusTrojan ( 0053d33d1 )
BitDefenderGeneric.Ransom.GandCrab.1DA8B53A
K7GWTrojan ( 0053d33d1 )
Cybereasonmalicious.1ff365
BitDefenderThetaAI:Packer.5657F44D1F
CyrenW32/S-4af35050!Eldorado
SymantecRansom.GandCrab!g4
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Gandcrab-6502432-0
KasperskyTrojan-Ransom.Win32.GandCrypt.jdv
AlibabaRansom:Win32/GandCrab.ec9f253d
NANO-AntivirusTrojan.Win32.Encoder.eykzmb
ViRobotTrojan.Win32.GandCrab.75264
RisingRansom.GandCrab!1.B8D6 (RDMK:cmRtazqED7hKTUZa1ZK3d+o86PeD)
Ad-AwareGeneric.Ransom.GandCrab.1DA8B53A
SophosMal/Generic-R + Troj/GandCrab-A
ComodoTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Encoder.27154
ZillyaTrojan.Generic.Win32.578013
TrendMicroRansom.Win32.GANDCRAB.SMIU
McAfee-GW-EditionBehavesLike.Win32.Generic.lt
EmsisoftTrojan.Agent (A)
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.Generic.bzloj
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=88)
MicrosoftRansom:Win32/GandCrab.E
ArcabitGeneric.Ransom.GandCrab.1DA8B53A
AhnLab-V3Trojan/Win32.Gandcrab.R224767
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.jdv
GDataWin32.Trojan-Ransom.GandCrab.D
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Chapak
ALYacGeneric.Ransom.GandCrab.1DA8B53A
TACHYONRansom/W32.GandCrab.75264.B
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMIU
TencentMalware.Win32.Gencirc.10b0863e
YandexTrojan.GenAsa!Tj3lAktP/7c
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GandCrab.B!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Ransom:Win32/GandCrab.E?

Ransom:Win32/GandCrab.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment