Categories: RansomTrojan

Trojan.Ransom.GandCrab.Gen.2 removal guide

The Trojan.Ransom.GandCrab.Gen.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.GandCrab.Gen.2 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Trojan.Ransom.GandCrab.Gen.2?


File Info:

crc32: 3AD09270md5: 017371120be0ebaa4b2d1ea213cb547bname: 017371120be0ebaa4b2d1ea213cb547bsha1: c8412b62a38c7f98605ef5ce6f380c7baa612948sha256: f1a4eb741a067f41b36d06bbddd3ab60b35dfde33fd340bb50354c3b36c88679sha512: 62a13c288167256eb2271a0bf3265e5e1fa80ee0b81413e38991e0ad30d4239238ed9910ae5beafb10305637787759efb04afbbfa19f0f471f00957a6fab0852ssdeep: 6144:ODP9qGYmZjU20AsdLyrhm5J5G2YW0CYby:6qGYmZpGLohm5bmGqytype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 2.13.5.66Translation: 0x0844 0x16d3

Trojan.Ransom.GandCrab.Gen.2 also known as:

MicroWorld-eScan Trojan.Ransom.GandCrab.Gen.2
FireEye Generic.mg.017371120be0ebaa
CAT-QuickHeal Trojan.Mauvaise.SL1
ALYac Trojan.Ransom.GandCrab.Gen.2
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Malware
K7AntiVirus Trojan ( 0053a0b51 )
BitDefender Trojan.Ransom.GandCrab.Gen.2
K7GW Trojan ( 0053a0b51 )
Cybereason malicious.20be0e
TrendMicro Ransom_GANDCRAB.SMALY-3
BitDefenderTheta Gen:NN.ZexaF.34084.pu1@aSrOIfkG
F-Prot W32/S-993b59b5!Eldorado
TrendMicro-HouseCall Ransom_GANDCRAB.SMALY-3
Avast Win32:RansomX-gen [Ransom]
ClamAV Win.Packed.Gandcrab-6552923-4
GData Trojan.Ransom.GandCrab.Gen.2
Kaspersky HEUR:Trojan.Win32.Generic
NANO-Antivirus Trojan.Win32.Encoder.fejium
ViRobot Trojan.Win32.GandCrab.Gen.A
Rising Ransom.GandCrab!1.BC55 (CLOUD)
Ad-Aware Trojan.Ransom.GandCrab.Gen.2
Sophos Mal/Agent-AUL
Comodo TrojWare.Win32.Ransom.GandCrab.GR@826oxk
F-Secure Heuristic.HEUR/AGEN.1038194
DrWeb Trojan.Encoder.24384
Zillya Trojan.GandCrypt.Win32.490
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
SentinelOne DFI – Malicious PE
Emsisoft Trojan.Ransom.GandCrab.Gen.2 (B)
APEX Malicious
Cyren W32/S-993b59b5!Eldorado
Jiangmin Trojan.PSW.Coins.sc
MaxSecure Ransomeware.CRAB.gen
Avira HEUR/AGEN.1038194
Endgame malicious (high confidence)
Arcabit Trojan.Ransom.GandCrab.Gen.2
SUPERAntiSpyware Ransom.GandCrab/Variant
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Skeeyah.A!rfn
TACHYON Ransom/W32.Agent.255497
AhnLab-V3 Win-Trojan/Gandcrab.Exp
Acronis suspicious
McAfee Trojan-FPST!017371120BE0
MAX malware (ai score=83)
VBA32 BScope.TrojanRansom.GandCrypt
Malwarebytes Trojan.MalPack
Panda Trj/Genetic.gen
Zoner Trojan.Win32.69730
ESET-NOD32 a variant of Win32/Kryptik.GIDB
Tencent Malware.Win32.Gencirc.10b586ee
Yandex Trojan.GandCrypt!
Ikarus Ransom.Win32.GandCrab
eGambit Unsafe.AI_Score_95%
Fortinet W32/GenKryptik.CNAR!tr
Webroot W32.Trojan.Ransom.GandCrab.Gen
AVG Win32:RansomX-gen [Ransom]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Win32/Trojan.Ransom.GandCrab.AX

How to remove Trojan.Ransom.GandCrab.Gen.2?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.1193900862 removal instruction

The Malware.AI.1193900862 is considered dangerous by lots of security experts. When this infection is active,…

18 seconds ago

Malware.AI.1522466034 malicious file

The Malware.AI.1522466034 is considered dangerous by lots of security experts. When this infection is active,…

42 seconds ago

How to remove “Fragtor.35742 (B)”?

The Fragtor.35742 (B) is considered dangerous by lots of security experts. When this infection is…

5 mins ago

Malware.AI.4082396169 malicious file

The Malware.AI.4082396169 is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago

MSILHeracles.134289 malicious file

The MSILHeracles.134289 is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago

Malware.AI.3800365927 removal instruction

The Malware.AI.3800365927 is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago