Ransom

How to remove “Ransom:Win32/Gandcrab.G!rfn”?

Malware Removal

The Ransom:Win32/Gandcrab.G!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Gandcrab.G!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Gandcrab.G!rfn?


File Info:

crc32: F9AF7119
md5: 6ec57cc3a371cedc25968bfcb9fb55ed
name: 6EC57CC3A371CEDC25968BFCB9FB55ED.mlw
sha1: 059f8cd2be84b8ed91f9e5638caba2e9695c2134
sha256: d64e00b082d3c834b668c6af577300cbe2a16f93a7291c1f993a65a949b63ed9
sha512: 347ed22a0ed4f03965c4462b40ac91400aecbbb2eaf54bda7c89c77d0edb6671c4bb86cf9c227ab98b6871b9a329fdeeb2da97bdc9db5314b51d3d9a58f84b23
ssdeep: 3072:9VwLp37ZXRRB0jy7CQS7uOCiijPYuOjH+Tx+/UyfywqHQT55Su8tJNB6:DwLh7BRVCMFPYuO4vyfyweNu8tJN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Gandcrab.G!rfn also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3953
ALYacTrojan.Ransom.Crysis
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.592
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Kryptik.fa7e977f
K7GWTrojan ( 00516fdf1 )
K7AntiVirusTrojan ( 00516fdf1 )
CyrenW32/Kryptik.LZ.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GLKU
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Encoder.acj
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Encoder.fkqqaw
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Encoder.Wtnx
Ad-AwareTrojan.Brsecmon.1
SophosML/PE-A + Mal/GandCrab-G
ComodoMalware@#3rx7rjfyokqhu
BitDefenderThetaGen:NN.ZexaF.34170.nuW@aevfATii
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dh
FireEyeGeneric.mg.6ec57cc3a371cedc
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Stealer.ei
WebrootW32.Adware.Installcore
AviraHEUR/AGEN.1102745
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.29B8D48
MicrosoftRansom:Win32/Gandcrab.G!rfn
ArcabitTrojan.Brsecmon.1
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win32.Agent.C2741886
McAfeeTrojan-FPST!6EC57CC3A371
MAXmalware (ai score=100)
VBA32BScope.Trojan.Propagate
MalwarebytesMalware.AI.1248292264
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!KfdxX7R+qb0
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GLKY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Gandcrab.G!rfn?

Ransom:Win32/Gandcrab.G!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment