Ransom

About “Ransom:Win32/GandCrab!pz” infection

Malware Removal

The Ransom:Win32/GandCrab!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/GandCrab!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • CAPE detected the Gandcrab malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ransom:Win32/GandCrab!pz?


File Info:

name: 1F45E570F31E9B2F6659.mlw
path: /opt/CAPEv2/storage/binaries/71b3c670a671e5057a1548534961eec06a136099784cc25261e49676ce8e9243
crc32: 69D51DAB
md5: 1f45e570f31e9b2f6659b6bccdf5a186
sha1: 0e6fcdbed152d552f65b5a9c475f0cc2643eae88
sha256: 71b3c670a671e5057a1548534961eec06a136099784cc25261e49676ce8e9243
sha512: a107793cb587208579068223f2a960eb9e4761f6eb72992c70e3d80137cda2efc64f2d7203321136b3a2afb750a89e959bc8443cd181d5464615c919a32b6263
ssdeep: 1536:/rsWDX9pwpQUMqqU+2bbbAV2/S2mr3IdE8mne0Avu5r++yy7CA7GcIaapavdv:/jDX9pwzMqqDL2/mr3IdE8we0Avu5r+g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3935B012AE18133E6E3FAB165B86E65543A3E145B2CBCD700EC1D3E1E269E24D35B5F
sha3_384: 0eddef1684179f6031a89a0acbd004b01a3c399727b782f3074a221ab0f536ee50bda18f36c820c826e3e52395457360
ep_bytes: 558bece8a8fdffff6a00ff1568911900
timestamp: 2018-02-03 18:58:37

Version Info:

0: [No Data]

Ransom:Win32/GandCrab!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.GandCrab.421801FB
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.mm
McAfeeRansomware-GJP!1F45E570F31E
Cylanceunsafe
SangforRansom.Win32.Gandcrab_1.se
K7AntiVirusRansomware ( 0053d33d1 )
K7GWRansomware ( 0053d33d1 )
Cybereasonmalicious.ed152d
SymantecRansom.GandCrab!g4
ESET-NOD32a variant of Win32/Filecoder.GandCrab.H
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Ransomware.Gandcrab-6667060-0
KasperskyTrojan-Ransom.Win32.GandCrypt.jzw
BitDefenderGeneric.Ransom.GandCrab.421801FB
NANO-AntivirusTrojan.Win32.Filecoder.kgozwu
AvastWin32:RansomX-gen [Ransom]
TencentTrojan-Ransom.Win32.GandCrab.16000553
SophosTroj/GandCrab-A
F-SecureTrojan.TR/Crypt.XPACK.Gen3
VIPREGeneric.Ransom.GandCrab.421801FB
TrendMicroRansom_GANDCRAB.SMALY-4
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Ransom.GandCrab.D
JiangminTrojan.GandCrypt.aij
VaristW32/GandCrab.AR.gen!Eldorado
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan[Ransom]/Win32.GandCrab
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Ransom.GandCrab.B@7kn2ff
ArcabitGeneric.Ransom.GandCrab.D66FA9FB
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.jzw
MicrosoftRansom:Win32/GandCrab!pz
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2425584
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.fyW@a4hMCKki
ALYacGeneric.Ransom.GandCrab.421801FB
VBA32BScope.Trojan.Chapak
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-4
RisingRansom.GandCrab!1.B8D6 (CLASSIC)
YandexTrojan.GenAsa!Tj3lAktP/7c
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GandCrab.B!tr.ransom
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom:Win32/GandCrab!pz?

Ransom:Win32/GandCrab!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment