Ransom

Ransom:Win32/GandCrab.EH!bit removal tips

Malware Removal

The Ransom:Win32/GandCrab.EH!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GandCrab.EH!bit virus can do?

  • Creates RWX memory
  • A process was set to shut the system down when terminated
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/GandCrab.EH!bit?


File Info:

crc32: 4F804028
md5: bdb769f7302b2035d81e34c5ed81ac55
name: BDB769F7302B2035D81E34C5ED81AC55.mlw
sha1: fb7df6135c713627c65751979cce56734bad79f6
sha256: f70d73b6c3f61f412567bf74d4f1fba052ddccf0f8b2e61a6c69de9c8c5e6ec1
sha512: 51d53eab274a047107bdb4c7d9914c7076718fe4a715246b5449faa4ad82974b4a05b0b3fda303679f767a1c8de4d61d7708c900996b10dc4fc89a6400805b11
ssdeep: 3072:UKwH7Fxw0GQi8SHa0jNwriVcJLLfOeMYU:XG3wq70pwrimxLw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/GandCrab.EH!bit also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Malware.Razy-6829823-0
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeTrojan-FQOA!BDB769F7302B
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.647
AegisLabTrojan.Win32.Encoder.4!c
SangforRansom.Win32.Gandcrab_3.se
K7AntiVirusTrojan ( 00545bf41 )
BitDefenderGeneric.Ransom.GandCrab5.C3863DCA
K7GWTrojan ( 00545bf41 )
Cybereasonmalicious.7302b2
ArcabitGeneric.Ransom.GandCrab5.C3863DCA
CyrenW32/GandCrab.AE.gen!Eldorado
SymantecRansom.GandCrab!g5
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Encoder.gen
AlibabaRansom:Win32/Genasom.ali1000102
NANO-AntivirusTrojan.Win32.Filecoder.fmnruw
SUPERAntiSpywareRansom.GandCrab/Variant
MicroWorld-eScanGeneric.Ransom.GandCrab5.C3863DCA
RisingTrojan.Filecoder!8.68 (CLOUD)
Ad-AwareGeneric.Ransom.GandCrab5.C3863DCA
SophosMal/Generic-S + Troj/Patched-BY
ComodoTrojWare.Win32.Ransom.GandCrab.F@82ddqu
F-SecureHeuristic.HEUR/AGEN.1102636
DrWebTrojan.Encoder.24384
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.GANDCRAB.SMILC
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.bdb769f7302b2035
EmsisoftGeneric.Ransom.GandCrab5.C3863DCA (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Encoder.fq
MaxSecureTrojan.Malware.73715490.susgen
AviraHEUR/AGEN.1102636
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Encoder
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/GandCrab.EH!bit
ViRobotTrojan.Win32.GandCrab.101376
ZoneAlarmHEUR:Trojan-Ransom.Win32.Encoder.gen
GDataGeneric.Ransom.GandCrab5.C3863DCA
AhnLab-V3Trojan/Win32.Gandcrab.R254874
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.gqW@aqwPyqi
ALYacTrojan.Ransom.GandCrab
VBA32BScope.Trojan.Dynamer
MalwarebytesRansom.GandCrab
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Filecoder.GandCrab.E
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMILC
TencentMalware.Win32.Gencirc.10b9a9ba
YandexTrojan.Monder.Gen!Pac.2
IkarusTrojan-Ransom.GandCrab
eGambitUnsafe.AI_Score_99%
FortinetW32/GandCrab_V5_2!tr.ransom
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.bf6

How to remove Ransom:Win32/GandCrab.EH!bit?

Ransom:Win32/GandCrab.EH!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment