Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2018

How to remove GandCrab 5.0.2 ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

GandCrab 5.0.2 — yet another version of GandCrab ransomware that emerged together with three other versions

GandCrab v5.0.2 ransomware is a malicious cryptovirus that locks data by using Salsa20 and RSA-2048 encryption algorithms. It emerged together with the GandCrab 5 and is using the same pattern using random characters to generate the file extension. To mark files that were encrypted by Gandcrab 5.0.2, the virus takes 10 random letters or less that it places at the end of each file name. According to one of our victims, his files were marked with the .bundvvi file extension, but other victims found .wrvoqvipr, and similar random characters added to their encrypted data. After this encryption[1] procedure is finished, the virus also creates a text file which is named by using the same characters used in the extension and a word “DECRYPT.” The note is asking to pay a ransom in exchange for the decrypted files, but keep in mind that this paying the ransom doesn't guarantee that your data will be presented with Gandcrab v5.0.2 decryptor.

Name GandCrab 5.0.2 ransomware
Type Cryptovirus
FAMILY GandCrab ransomware
SUB-Versions
File extension 6-10 random characters
Encryption methods Salsa20 and RSA-2048
Ransom note [ransom characters]-DECRYPT.txt
Distribution Fallout exploit kit
Decryption There is no decryption tool for this variant, but previously discovered vaccine works for this second variant od GandCrab v5
Elimination Use FortectIntego for GandCrab 5.0.2 ransomware removal

The ransomware virus is one of the most recent variants in the notorious ransomware[2] family that is known to encrypt users' data and demand a hefty amount in Bitcoin as the only way to unlock them. This particular version came out on the 1st of October and has been spreading around with the help of Fallout exploit kit since then. 

Immediately after the encryption process is finished, the ransomware virus generates a file with some instructions and more details about the initial attack. Since the appearance of the first variant of GandCrab family, these ransom messages have been placed in the HTML file. At the moment, the ransom note file is created as a text file. The particular GandCrab 5.0.2 ransomware creates a ransom note named as RANDOM FILE EXTENSION CHARACTERS-DECRYPT.txt and drops it on every folder that contains encoded files. It reads the following:

—= GANDCRAB V5.0.2 =—
Attention!
All your files, documents, photos, databases and other important files are encrypted and have the extension: {5 random letters}
The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.
The server with your key is in a closed network TOR. You can get there by the following ways:

———————————————————————–
| 0. Download Tor browser – https://www.torproject.org/

| 1. Install Tor Browser
| 2. Open Tor Browser
| 3. Open link in TOR browser http://gandcrab{random}/{random}
| 4. Follow the instructions on this page

On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.

ATTENTION!
IN ORDER TO PREVENT DATA DAMAGE:
• DO NOT MODIFY ENCRYPTED FILES
• DO NOT CHANGE DATA BELOW

As you can see in the quote, there are not many details about an encryption process or the ransom amount. However, when you follow these instructions and go to TOR browser, where the payment page is hosted, you can see your ransom amount, the time you have left to pay, and other information.

However, like any other researcher,[3] we do not recommend paying for GandCrab 5.0.2 ransomware virus developers. You should avoid contacting cybercriminals in any way and focus only on the ransomware removal instead. Then, when your device is clean, you can try recovery methods displayed down below or replace your data from a safe backup.

GandCrab 5.0.2 ransomware removal can be performed using your trusty antivirus or a reputable anti-malware program. Antivirus developers, who have already included this particular variant of ransomware into the data base of their software, detect the main its file under different names:

  • Ransom.GandCrab
  • ML.Attribute.HighConfidence
  • Trojan-Ransom.Win32.GandCrypt.fbd
  • TR/AD.GandCrab.wizji
  • Trojan[Ransom]/Win32.GandCrypt
  • Ransom:Win32/GandCrab.MTC!bit
  • Trojan-Ransom.Win32.GandCrypt.fbd
  • etc.

You need to remove GandCrab 5.0.2 ransomware as soon as possible because the ransom amount may double in time and, if you wait too long, criminals behind this threat can affect the system of your device in more prominent ways. This is a serious cyber infection, and you need to employ tools like FortectIntego for the correct virus elimination.

Ransomware developers use different tools set  for distribution

Since crypto viruses are one of the most dangerous cyber threats, these techniques of distribution may vary from variant to variant and be more dangerous than you think. The most common way of spreading these cyber infections are spam email attachments containing malicious files or directs ransomware payload. 

However, these few versions of ransomware in particular family of threats are known to be distributed using exploit kits and various system vulnerabilities. Fallout exploit kit, in particular, is used in this attack, alongside Adobe Flash and Task Scheduler ALPC vulnerabilities. 

Also, ransomware can use brute-force to break through unprotected RDP and install malware directly or spread different malicious programs that are designed to infect the device with ransomware payload.

Get rid of GandCrab 5.0.2 ransomware right now

You should remove GandCrab 5.0.2 ransomware as soon as possible and using reputable tools like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Cybercriminals may say that virus elimination may lead to more damage, but that statement is only for tricking you and giving more time for the developers.

GandCrab 5.0.2 ransomware removal is important if you want to get your files back and your device thoroughly cleaned. It is not easy but manageable and possible. You can follow further instructions down below. These step-by-step guides explain how to protect your system and get rid of the ransomware.

As a bonus, you can find decryption methods down below. If you do not have correct backups saved on an external device or cloud service, you can try one of the software designed to recover files that are listed below the article. 

Be the first to comment

Read in your language

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.