Ransom

What is “Ransom:Win32/Gpcode.B”?

Malware Removal

The Ransom:Win32/Gpcode.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Gpcode.B virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/Gpcode.B?


File Info:

crc32: 7A6E8335
md5: 0c361f940981a75e635d5521b0a60fec
name: 0C361F940981A75E635D5521B0A60FEC.mlw
sha1: 3a6172c8c55f989cd4e52aa6b9ea6cd4b424f71f
sha256: 15d6b716edc96f9ed822759cc59a297beb1200090dee130e80688c9466441f7d
sha512: 541e239d14a1f710d2b85116b23af0202ee5bdce65d59db58a516cf740723b44c522147ccd1cde3bd18f95771b7578656b2755d5792779da2ba701aa319598d3
ssdeep: 1536:n+qKEk49s2/lYsQS6NNCb4GgUNQBCNkWhrDVX8:nLps2M7NY9/NQBCeWhr
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/Gpcode.B also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004b424e1 )
DrWebTrojan.PGPCrypt.3
CynetMalicious (score: 100)
ALYacTrojan.Gpcode.C
CylanceUnsafe
ZillyaTrojan.Gpcode.Win32.3
SangforRansom.Win32.Gpcode.e
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Gpcode.e60bcd05
K7GWTrojan ( 004b424e1 )
Cybereasonmalicious.40981a
CyrenW32/Trojan.QCYO-6626
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Gpcode.E
APEXMalicious
AvastWin32:Pgcoder
ClamAVWin.Trojan.Gpcode-7
KasperskyTrojan-Ransom.Win32.Gpcode.e
BitDefenderTrojan.Gpcode.C
NANO-AntivirusTrojan.Win32.Gpcode.esig
MicroWorld-eScanTrojan.Gpcode.C
TencentWin32.Virus.Gpcode.Fry
Ad-AwareTrojan.Gpcode.C
SophosMal/Generic-R + Troj/Gpcode-C
ComodoWin32.Gpcode.E@2xru
BitDefenderThetaGen:NN.ZexaF.34688.dmGfaCKuPjp
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_PGPCODER.B
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeTrojan.Gpcode.C
EmsisoftTrojan.Gpcode.C (B)
JiangminTrojan/Gpcode.c
WebrootTrojan:Win32/Gpcode.B
AviraTR/Gpcode.E
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Gpcode.B
AegisLabTrojan.Win32.Gpcode.tqRI
GDataTrojan.Gpcode.C
TACHYONTrojan/W32.Gpcode.118784
AhnLab-V3Trojan/Win32.HDC.C26217
McAfeeArtemis!0C361F940981
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Gpcode
PandaTrj/PGPCoder.B
TrendMicro-HouseCallTROJ_PGPCODER.B
RisingRansom.Gpcode!8.568 (CLOUD)
YandexTrojan.GenAsa!kT/sDFOc0YI
IkarusTrojan-Ransom.Agent
MaxSecureTrojan.Malware.2018611.susgen
FortinetW32/Gpcode.C!tr
AVGWin32:Pgcoder
Paloaltogeneric.ml

How to remove Ransom:Win32/Gpcode.B?

Ransom:Win32/Gpcode.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment