Remove Gandcrab 5.0.4 ransomware (Removal Instructions) - updated Dec 2018
Gandcrab 5.0.4 virus Removal Guide
What is Gandcrab 5.0.4 ransomware?
GandCrab 5.0.4 ransomware is a decryptable variant of GandCrab family
GandCrab 5.0.4 is ransomware that was first spotted in early October 2018 and is a variant of the infamous GandCrab virus. Upon infiltration, it encrypts data using RSA and Salsa 20 encryption algorithms, adds a random extension (for example, .GHMFJ) to each of the personal files, and drops a ransom note [random]-DECRYPT.txt. It is uploaded from a C2 server that is controlled by hackers to make sure victims are aware of what happened and what to do next. To retrieve access to personal data, users are asked to pay up in Bitcoin or Dash cryptocurrency. GandCrab v5.0.4 also swaps the desktop wallpaper to the one which looks like a brief ransom note. This variant of the virus is propagated with the help of Fallout exploit kit,[1] the fake Windows defender update and some other distribution methods propagating output.114727762.txt and similar files which are malicious. Luckily, some virus versions are already decryptable[2] with the help of Bitdefender’s decryptor. Those who are unlucky can also try a tool provided by McAfee’s security researcher Raj Samani.[3] We provide all the links below.
Summary | |
Name | —= Gandcrab v5.0.4 =— |
Type | Ransomware |
Related | |
Previous versions | GandCrab 5.0.1, GandCrab 5.0.2, Gandcrab 5.0.3 |
Spotted | Early October 2018 |
File extension | Randomly generated characters, e.g. .GTELNIVKYF, .OBKBTXTN, .LGAWPULM |
Cipher used | RSA and Salsa20 |
Ransom note | [random]-DECRYPT.txt |
Distribution | Vulnerabilities, exploits, spam emails, malicious websites, etc. |
Elimination | Download anti-malware software ReimageIntego or SpyHunter 5Combo Cleaner and perform a full system scan |
Decryptable? | Yes. Use GandCrab 5.0.4 decryptor to recover locked data or try another tool created by a different security researcher. |
To distribute malicious payload of earlier variants, hackers have been using RIG and GradSoft exploit kits.[4] However, v5 utilizes the new Fallout exploit kit, as well as spam emails, malicious websites and ALPC Task Scheduler Zero-day exploit,[5] making Gandcrab 5.0.4 ransomware one of the most rampantly growing threats in the past few weeks.
Just as like its previous variants, Gandcrab v5.0.4 virus uses sophisticated encryption algorithm RSA and Salsa20 to encrypt files such as videos, pictures, images, databases documents, and renders them useless. To retrieve access to the data, victims are urged to contact criminals via the TOR browser or a provided email address. The full ransomware note reads the following:
—= GANDCRAB V5.0.4 =—
Attention!
All your files, documents, photos, databases and other important files are encrypted and have the extension: .OBKBTXTNThe only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.
The server with your key is in a closed network TOR. You can get there by the following ways:
| 0. Download Tor browser – hxxps://www.torproject.org/
| 1. Install Tor browser
| 2. Open Tor Browser
| 3. Open link in TOR browser: hxxp://gandcrabmfe6mnef.onion/bba886b160b8e97e
| 4. Follow the instructions on this page—————–
On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.
ATTENTION!
IN ORDER TO PREVENT DATA DAMAGE:
* DO NOT MODIFY ENCRYPTED FILES
* DO NOT CHANGE DATA BELOW—BEGIN GANDCRAB KEY—
–
—END GANDCRAB KEY——BEGIN PC DATA—
–
—END PC DATA—
———————
As usual, experts recommend avoiding any contact with cybercriminals and taking care of Gandcrab 5.0.4 ransomware removal instead. Hackers should never be trusted as they use clever social engineering to trick people into paying money. Malware authors can simply ignore you after the ransom is paid (they usually demand between $800 and $2400 in Bitcoin or Dash), so you will end up losing both – files and money. Thus, do not risk being a victim of a scam, as such scenario is highly plausible.
To remove Gandcrab 5.0.4 ransomware, you should download and install comprehensive security software, bring it up to date, enter Safe Mode with Networking and perform a full system scan. This should disable the virus temporary and allow the security program to operate correctly.
Only after Gandcrab v5.0.4 elimination, you should attempt file recovery. The latest variant of GandCrab is already decryptable. The tools that you can use are provided in our recovery guide below. Unfortunately, we have been informed that for some victims the decryption tool fails to work. In this case, try third-party methods.
Patch your software on time and be aware of spam email campaigns
Since the latest variant utilizes Fallout exploit kit, as well as vulnerability, make sure you patch your software regularly. Security updates are vital for any machine, as it blocks malicious payloads bypassing bugs inside the software. It is equally important to update security software on a regular basis, as detection databases are updated daily.
Nevertheless, be aware that new malware strings are emerging every day, so staying alert while browsing the internet and opening spam emails are vital to virtual safety. We recommend you stay away from the torrent, file-sharing, gambling, porn,[6] and similar insecure sites. Likewise, opening email attachments from an unknown source is also a bad idea. If you are not sure if the email is legitimate, contact the company that is allegedly sending it, and confirm that email is not fake. Also, scanning the attached file with security software is recommended.
GandCrab 5.0.4 virus elimination and file recovery
Despite crooks’ warnings, you should not delay Gandcrab 5.0.4 ransomware removal. The malware might compromise the safety of the machine, and allow other dangerous infections to slip through. Therefore, if you still do not have security software, download and install ReimageIntego or SpyHunter 5Combo Cleaner and run a full system scan. In some cases, the cyber threat might block anti-malware software, so entering Safe Mode with Networking might be a way out.
Only after you remove Gandcrab 5.0.4 virus, you can attempt file recovery. If you have backups available – do not connect the external device to the infected machine, of all your backups will be ruined and encrypted as well! If you do not have backups, follow our guide below to try alternative methods designed to help victims decrypt Gandcrab 5.0.4. There is also an official tool from Bitdefender that you can use to recover encrypted data. It is provided in the link below.
Getting rid of Gandcrab 5.0.4 virus. Follow these steps
Manual removal using Safe Mode
To remove Gandcrab v5.0.4 ransomware safely, enter Safe Mode with Networking
Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.
Step 1. Access Safe Mode with Networking
Manual malware removal should be best performed in the Safe Mode environment.
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. – it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.
Windows 10 / Windows 8
- Right-click on Start button and select Settings.
- Scroll down to pick Update & Security.
- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.
- Select Troubleshoot.
- Go to Advanced options.
- Select Startup Settings.
- Press Restart.
- Now press 5 or click 5) Enable Safe Mode with Networking.
Step 2. Shut down suspicious processes
Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Click on More details.
- Scroll down to Background processes section, and look for anything suspicious.
- Right-click and select Open file location.
- Go back to the process, right-click and pick End Task.
- Delete the contents of the malicious folder.
Step 3. Check program Startup
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Go to Startup tab.
- Right-click on the suspicious program and pick Disable.
Step 4. Delete virus files
Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:
- Type in Disk Cleanup in Windows search and press Enter.
- Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
- Scroll through the Files to delete list and select the following:
Temporary Internet Files
Downloads
Recycle Bin
Temporary files - Pick Clean up system files.
- You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):
%AppData%
%LocalAppData%
%ProgramData%
%WinDir%
After you are finished, reboot the PC in normal mode.
Remove Gandcrab 5.0.4 using System Restore
You can also disable the virus using System Restore:
-
Step 1: Reboot your computer to Safe Mode with Command Prompt
Windows 7 / Vista / XP- Click Start → Shutdown → Restart → OK.
- When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
-
Select Command Prompt from the list
Windows 10 / Windows 8- Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
- Now select Troubleshoot → Advanced options → Startup Settings and finally press Restart.
-
Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window.
-
Step 2: Restore your system files and settings
-
Once the Command Prompt window shows up, enter cd restore and click Enter.
-
Now type rstrui.exe and press Enter again..
-
When a new window shows up, click Next and select your restore point that is prior the infiltration of Gandcrab 5.0.4. After doing that, click Next.
-
Now click Yes to start system restore.
-
Once the Command Prompt window shows up, enter cd restore and click Enter.
Bonus: Recover your data
Guide which is presented above is supposed to help you remove Gandcrab 5.0.4 from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.If your files are encrypted by Gandcrab 5.0.4, you can use several methods to restore them:
Data Recovery Pro can help you with file decryption
Data Recovery Pro was originally designed to help users who accidentally deleted or otherwise corrupted personal files. Nevertheless, this application was also useful in some cases of ransomware infections.
- Download Data Recovery Pro;
- Follow the steps of Data Recovery Setup and install the program on your computer;
- Launch it and scan your computer for files encrypted by Gandcrab 5.0.4 ransomware;
- Restore them.
Make use of Windows Previous Version feature
This method allows you to recover files one-by-one, so retrieving large amounts of data might be impossible
- Find an encrypted file you need to restore and right-click on it;
- Select “Properties” and go to “Previous versions” tab;
- Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.
ShadowExplorer can utilize Shadow Volume Copies to recover files encrypted by Gandcrab 5.0.4 ransomware
If the virus failed to remove Shadow Volume Copies, this tool will recover all your files.
- Download Shadow Explorer (http://shadowexplorer.com/);
- Follow a Shadow Explorer Setup Wizard and install this application on your computer;
- Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
- Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.
The official GanCrab 5.0.4 decryptor is already available
Recently, Bitdefender released an official tool to help the affected users recover encrypted data. You can download it here.
Another tool was released by another security expert and can be downloaded from here. While the tool is initially created for all versions up to 5.0.3, it might work for 5.0.4 in some cases.
Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Gandcrab 5.0.4 and other ransomwares, use a reputable anti-spyware, such as ReimageIntego, SpyHunter 5Combo Cleaner or Malwarebytes
How to prevent from getting ransomware
Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices. Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using Private Internet Access VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings. Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact – you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use Data Recovery Pro for the data restoration process.
- ^ New Exploit Kit Fallout Delivering Gandcrab Ransomware. Trend Micro. Malware researchers.
- ^ Linas Kiguolis. Free decryptor released for GandCrab versions 1, 4, and 5. 2-spyware. Cybersecurity news and articles.
- ^ Raj Samani. Free decryption tool for #GandCrab #ransomware. Twitter. Social Network.
- ^ Bradley Barth. RIG and GrandSoft exploit kits shell out new GandCrab ransomware. SC Media. Cybersecurity site.
- ^ Johnathan Crowe. Windows Task Scheduler ALPC Zero-Day Exploited in the Wild: What You Need to Know. Barky, Security research.
- ^ Andrew Couts. Watching online porn is a good way to get yourself blackmailed by a hacker. Digital Trends. Security and tech site.