Malware

Win32/Filecoder.GandCrab.E information

Malware Removal

The Win32/Filecoder.GandCrab.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.GandCrab.E virus can do?

  • Creates RWX memory
  • A process was set to shut the system down when terminated
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Win32/Filecoder.GandCrab.E?


File Info:

crc32: 42D262E1
md5: ba2960ce267dc0f11e2683679ce038f7
name: BA2960CE267DC0F11E2683679CE038F7.mlw
sha1: 7a6997490eea5ad21ec17367fb7a64fa5916f5e3
sha256: fb136c8360d1a5ab80f61109c55c5a788aa1d8796d1e75aca8c1a762b598d3f4
sha512: 86baa9998be044095ac4556d29ee4eb0f6622b81f1c176896d490335579b8977fd7cf7fa86dc6750e5ca920493ee1659ae9e836c3706bf1a1d2987898cdf7519
ssdeep: 3072:UKwH7Fxw0GQi8SHa0jNwriVcJLLfONMYU:XG3wq70pwrimxLp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.GandCrab.E also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
MicroWorld-eScanGeneric.Ransom.GandCrab5.C3863DCA
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Win32/Ransom.GandCrab.HxQBXK8A
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.647
AegisLabTrojan.Win32.Encoder.4!c
SangforRansom.Win32.Gandcrab_3.se
K7AntiVirusTrojan ( 00545bf41 )
BitDefenderGeneric.Ransom.GandCrab5.C3863DCA
K7GWTrojan ( 00545bf41 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitGeneric.Ransom.GandCrab5.C3863DCA
BitDefenderThetaGen:NN.ZexaF.34590.gqW@aqwPyqi
CyrenW32/GandCrab.AE.gen!Eldorado
SymantecRansom.GandCrab!g5
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Razy-6829823-0
KasperskyHEUR:Trojan-Ransom.Win32.Encoder.gen
AlibabaRansom:Win32/Genasom.ali1000102
NANO-AntivirusTrojan.Win32.Filecoder.fmnruw
ViRobotTrojan.Win32.GandCrab.101376
TencentMalware.Win32.Gencirc.10b9a9ba
Ad-AwareGeneric.Ransom.GandCrab5.C3863DCA
EmsisoftGeneric.Ransom.GandCrab5.C3863DCA (B)
ComodoTrojWare.Win32.Ransom.GandCrab.F@82ddqu
F-SecureHeuristic.HEUR/AGEN.1102636
TrendMicroRansom.Win32.GANDCRAB.SMILC
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.ba2960ce267dc0f1
SophosMal/Generic-S + Troj/Patched-BY
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.Encoder.fq
AviraHEUR/AGEN.1102636
Antiy-AVLTrojan[Ransom]/Win32.Encoder
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/GandCrab.EH!bit
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmHEUR:Trojan-Ransom.Win32.Encoder.gen
GDataGeneric.Ransom.GandCrab5.C3863DCA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gandcrab.R254874
Acronissuspicious
McAfeeTrojan-FQOA!BA2960CE267D
MAXmalware (ai score=100)
VBA32BScope.Trojan.Dynamer
MalwarebytesRansom.GandCrab
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Filecoder.GandCrab.E
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMILC
RisingTrojan.Filecoder!8.68 (CLOUD)
YandexTrojan.Monder.Gen!Pac.2
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GandCrab_V5_2!tr.ransom
AVGWin32:Trojan-gen
Cybereasonmalicious.e267dc
Paloaltogeneric.ml
MaxSecureTrojan.Malware.73715490.susgen

How to remove Win32/Filecoder.GandCrab.E?

Win32/Filecoder.GandCrab.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment