Ransom

Ransom:Win32/GandCrab!pz (file analysis)

Malware Removal

The Ransom:Win32/GandCrab!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GandCrab!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • CAPE detected the Gandcrab malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ransom:Win32/GandCrab!pz?


File Info:

name: 0BBCAD920E5E850C44C8.mlw
path: /opt/CAPEv2/storage/binaries/9097fd96f783a0aa3c7670aa9d936956c6557a8e8ea3f0bd48f6f3e2bc806cee
crc32: 9423DA5E
md5: 0bbcad920e5e850c44c8352bc925979d
sha1: dc20f4b0a058bfb9cf4fb9072946f57327ea3b2b
sha256: 9097fd96f783a0aa3c7670aa9d936956c6557a8e8ea3f0bd48f6f3e2bc806cee
sha512: e29bb7e7096fdb8e486f7a1977e7ed319abbdf4b6d29306ce1717aa2bdb4d4bf991ddfbfe20f35dd68ce25ff8cd789d5aa3abad56b94e01c9022e7e41aad6790
ssdeep: 1536:RrsWDX9pwpQUMqqU+2bbbAV2/S2mr3IdE8mne0Avu5r++yy7CA7GcIaapavdv:RjDX9pwzMqqDL2/mr3IdE8we0Avu5r+g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116935B012AE18133E6E3FAB165B86E65543A3E145B2CBCD700EC1D3E1E269E24D35B5F
sha3_384: a3c98a83b2968e85c4eb74812c42ce124c5827b5ba302ad316e21e378f601b7a3d463ae6dff66b3ad409a573f43b80ca
ep_bytes: 558bece8a8fdffff6a00ff1568911900
timestamp: 2018-02-03 18:58:37

Version Info:

0: [No Data]

Ransom:Win32/GandCrab!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGeneric.Ransom.GandCrab.3D674B8A
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.mm
McAfeeRansomware-GJP!0BBCAD920E5E
MalwarebytesGeneric.Malware.AI.DDS
SangforRansom.Win32.Gandcrab_1.se
K7AntiVirusRansomware ( 0053d33d1 )
K7GWRansomware ( 0053d33d1 )
Cybereasonmalicious.0a058b
ArcabitGeneric.Ransom.GandCrab.3D674B8A
SymantecRansom.GandCrab!g4
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Ransomware.Gandcrab-6667060-0
KasperskyTrojan-Ransom.Win32.GandCrypt.jzw
BitDefenderGeneric.Ransom.GandCrab.3D674B8A
NANO-AntivirusTrojan.Win32.Filecoder.kgozwu
AvastWin32:RansomX-gen [Ransom]
TencentTrojan-Ransom.Win32.GandCrab.16000553
SophosTroj/GandCrab-A
F-SecureTrojan.TR/Crypt.XPACK.Gen3
VIPREGeneric.Ransom.GandCrab.3D674B8A
TrendMicroRansom_GANDCRAB.SMALY-4
EmsisoftTrojan.Agent (A)
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.GandCrypt.aij
VaristW32/GandCrab.AR.gen!Eldorado
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan[Ransom]/Win32.GandCrab
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
MicrosoftRansom:Win32/GandCrab!pz
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.jzw
GDataWin32.Trojan-Ransom.GandCrab.D
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2425584
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.fyW@a4hMCKki
ALYacGeneric.Ransom.GandCrab.3D674B8A
VBA32BScope.Trojan.Chapak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-4
RisingRansom.GandCrab!1.B8D6 (CLASSIC)
YandexTrojan.GenAsa!Tj3lAktP/7c
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GandCrab.B!tr.ransom
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom:Win32/GandCrab!pz?

Ransom:Win32/GandCrab!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment