Trojan

Trojan:Win32/GandCrab.VDSK!MTB removal guide

Malware Removal

The Trojan:Win32/GandCrab.VDSK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/GandCrab.VDSK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipv4bot.whatismyipaddress.com
ns1.virmach.ru
politiaromana.bit
malwarehunterteam.bit
ns2.virmach.ru
gdcb.bit

How to determine Trojan:Win32/GandCrab.VDSK!MTB?


File Info:

crc32: 242F8A4C
md5: 150b3c6d181a38b28a67b4c222837104
name: 150B3C6D181A38B28A67B4C222837104.mlw
sha1: b6341395ce8fe8a232bea5c125dee5e6f6b6bd5d
sha256: 4dccb90243da01d9cb9de970b67e57776d1eaaea8a235f5375baa1472f3333ac
sha512: 71a60d494542dae5cc1d3a9737f83a67b55066a4bd3d0275a5ed9f3bfb30c107a8672ff5e101034f0fe25f6fab61779312488109b7f464cf036399f354f3d59d
ssdeep: 3072:SWLITGkPxR0TYRJztVY0vRDMxPslhFQ9zdVsT4ab3Wu7jQRv+7xbTM9GZq:SWL+GVTY7DSxPslh+9pYWu7jQFMQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/GandCrab.VDSK!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CWCG
FireEyeGeneric.mg.150b3c6d181a38b2
CAT-QuickHealTrojan.Chapak.A03
Qihoo-360Win32/Trojan.Chapak.HwoCWIcA
McAfeePacked-FBN!150B3C6D181A
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.865
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 0052cc321 )
BitDefenderTrojan.Agent.CWCG
K7GWTrojan ( 0052cc321 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Gandcrab.BH.gen!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Dropper.Emotet-6526410-0
KasperskyTrojan.Win32.Chapak.bio
AlibabaTrojan:Win32/Chapak.94253cf5
NANO-AntivirusTrojan.Win32.Chapak.eyvram
ViRobotTrojan.Win32.GandCrab.Gen.A
AegisLabTrojan.Win32.Panda.tplo
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
Ad-AwareTrojan.Agent.CWCG
EmsisoftTrojan.Agent.CWCG (B)
ComodoTrojWare.Win32.Suloc.D@7kjiha
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop8.1783
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.GANDCRAB.SMLA.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-R + Mal/Agent-AUL
IkarusTrojan.Kryptik
JiangminTrojanDownloader.Upatre.aivn
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/GandCrab.VDSK!MTB
ArcabitTrojan.Agent.CWCG
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmTrojan.Win32.Chapak.bio
GDataTrojan.Agent.CWCG
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.nuX@aOMgczgi
ALYacTrojan.Agent.CWCG
TACHYONRansom/W32.GandCrab
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GEGZ
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMLA.hp
TencentMalware.Win32.Gencirc.10b17f3c
YandexTrojan.Chapak!YheiXsTHYVs
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HCUD!tr
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.d181a3
Paloaltogeneric.ml
MaxSecureRansomeware.CRAB.gen

How to remove Trojan:Win32/GandCrab.VDSK!MTB?

Trojan:Win32/GandCrab.VDSK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment