GandCrab v5.0.3 ransomware – the third subversion of a notorious Gandcrab 5

GandCrab v5.0.3 ransomware is a sub-variant of GandCrab v5 and showed up mid-October 2018. Malware usually breaks in via spam emails or by using weak RDP,[1] as well as exploit kits (such as Fallout EK)[2] and then uses a strong encryption algorithm to lock up data. Files do not get corrupted, but instead, a file extension of five random characters is added, preventing users from accessing them. GandCrab 5.0.3 virus then leaves a ransom note [5 random characters]-DECRYPT.txt behind, explaining what victims should do next. Additionally, the wallpaper is also swapped to a brief message from malware authors. To retrieve personal files, users are asked to pay a ransom of $400-2400 in Bitcoin or Dash cryptocurrency. The good news is that malware is already decryptable. Besides, users can use the special vaccine[3] to prevent file encryption entirely, as long as it is applied before the infection.
| Summary | |
| Name | GandCrab v5.0.3 |
| Type | Ransomware |
| Related versions | Gandcrab 5.0.1, GandCrab v5.0.2, GandCrab 5.0.4 |
| Cipher used | Salsa20 and RSA-2048 |
| Extension | .[5 random characters] |
| Ransom note | [5 random characters]-DECRYPT.txt |
| Distribution | Exploit kits, phishing emails, weak RDP, etc. |
| Elimination | Use FortectIntego or SpyHunterCombo Cleaner to eliminate the virus |
| Decryption process | Download GandCrab 5.0.3 decryptor |
Since version 5 release in late September, GandCrab grew rampant with new version releases, resulting in 4 sub-variants coming out in a short period of time. All cyber threats are using Salsa20 and RSA-2048 to encode data, and a random combination of characters as a file extension. According to cybercriminals, such method allows them to obfuscate and complicate GandCrab 5.0.3 removal process.
The main file dropper is JavaScript file called GandCrab 5.0.3 downloader.js, which once executed, launches another two executables – dsoyaltj.exe and Wermgr.exe. These processes provide malware administrative rights which can then modify Windows Registry and other vital settings.
After file encryption, the malware drops ransom note into each of the affected folders and includes the following message:
—= GANDCRAB V5.0.3 =—
Attention!
All your files, documents, photos, databases and other important files are encrypted and have the extension: {5 random letters}
The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.
The server with your key is in a closed network TOR. You can get there by the following ways:
———————————————————————–
| 0. Download Tor browser – https://www.torproject.org/
| 1. Install Tor Browser
| 2. Open Tor Browser
| 3. Open link in TOR browser http://gandcrabmfe6mnef.onion/[unique_ID]
| 4. Follow the instructions on this page
On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.
ATTENTION!
IN ORDER TO PREVENT DATA DAMAGE:
• DO NOT MODIFY ENCRYPTED FILES
• DO NOT CHANGE DATA BELOW
Once users enter the provided URL, they can see further details on how to process the payment and allegedly receive the decryptor. However, experts[4] do not recommend contacting criminals, as loss of money is likely. Instead, users should ignore the warnings and the ransom note, and remove GandCrab 5.0.3 ransomware from their computers. To make sure that the process is smooth, users should reboot in Safe Mode with Networking to temporary disable the virus and perform system scan using FortectIntego, SpyHunterCombo Cleaner or another trusted security software.
Only after GandCrab v5.0.3 ransomware is eliminated, victims can proceed with file recovery. Those who keep backups are in luck – it assures a 100% data recovery. Users who did not prepare a backup, should not give up because researchers at BitDefender have already presented a free decryption tool. All the instructions on how to get it are provided below.

Exploit kits and spam – the main ways used by ransomware to find its way into the system
Internet security is often underestimated by users, as they are extremely careless when it comes to it. Furthermore, negligence might be initiated by a simple lack of knowledge. Unfortunately, those who do not know how malware is distributed and how it infects computers are usually the victims.
Ransomware is one of the most wide-spread cyber threats when it comes to money extortion. Thus, users should always back up their systems, as no security measures can guarantee 100% protection. Nevertheless, several actions can significantly reduce the risk of infection, such as:
- Prompt Windows and other software updates;
- Powerful security software;
- File-sharing, torrent, and similar dangerous site avoidance;
- Strong passwords, frequently changed;
- Caution when opening spam emails, their links, and attachments.
The sooner you delete GandCrab 5.0.3 from your computer, the more files you can save
There are many people who get infected with a virus and suddenly ask “What should I do now?”. First of all, users should realize that the infection is finished, their files are encrypted, and now it is time to deal with the whole situation. The very first step after discovering your encrypted files is GandCrab 5.0.3 removal. There is no point in trusting the ransom note that declares that you need to send your ransom to cybercriminals and they will eliminate the virus for you.
If you are blocked, to remove GandCrab 5.0.3 virus, you should first enter Safe Mode with Networking, as explained below. After the boot, download and install reputable security software, and then perform a full system scan. Manual virus elimination is impossible for regular users, so do not waste your time (additionally, it can result in system failure, and then a complete reinstall of Windows will be needed).
Next, move on to files' recovery. The easiest way to get access to your data is using backups. If you don't have them, try methods that are presented below to recover files encrypted by GandCrab 5.0.3. You should definitely try using the official BitDefender decryptor. For the future, make sure you take care of the safety of your data by saving at least three copies of the save file in different locations.[5]
Was this guide helpful?
Be the first to comment