Gandcrab 5.0.4 ransomware (Removal Instructions) - updated Dec 2018

Gandcrab 5.0.4 virus Removal Guide

What is Gandcrab 5.0.4 ransomware?

GandCrab 5.0.4 ransomware is a decryptable variant of GandCrab family

GandCrab 5.0.4 ransomwareGandCrab 5.0.4 ransomware is a data locking virus that is capable of locking all personal files on the system

GandCrab 5.0.4 is ransomware that was first spotted in early October 2018 and is a variant of the infamous GandCrab virus. Upon infiltration, it encrypts data using RSA and Salsa 20 encryption algorithms, adds a random extension (for example, .GHMFJ) to each of the personal files, and drops a ransom note [random]-DECRYPT.txt. It is uploaded from a C2 server that is controlled by hackers to make sure victims are aware of what happened and what to do next. To retrieve access to personal data, users are asked to pay up in Bitcoin or Dash cryptocurrency. GandCrab v5.0.4 also swaps the desktop wallpaper to the one which looks like a brief ransom note. This variant of the virus is propagated with the help of Fallout exploit kit,[1] the fake Windows defender update and some other distribution methods propagating output.114727762.txt and similar files which are malicious. Luckily, some virus versions are already decryptable[2] with the help of Bitdefender’s decryptor. Those who are unlucky can also try a tool provided by McAfee’s security researcher Raj Samani.[3] We provide all the links below.

Name —= Gandcrab v5.0.4 =—
Type Ransomware
Previous versions GandCrab 5.0.1, GandCrab 5.0.2, Gandcrab 5.0.3
Spotted Early October 2018
File extension Randomly generated characters, e.g. .GTELNIVKYF, .OBKBTXTN, .LGAWPULM
Cipher used RSA and Salsa20
Ransom note [random]-DECRYPT.txt
Distribution Vulnerabilities, exploits, spam emails, malicious websites, etc.
Elimination Download anti-malware software ReimageIntego or SpyHunter 5Combo Cleaner and perform a full system scan
Decryptable? Yes. Use GandCrab 5.0.4 decryptor to recover locked data or try another tool created by a different security researcher.

To distribute malicious payload of earlier variants, hackers have been using RIG and GradSoft exploit kits.[4] However, v5 utilizes the new Fallout exploit kit, as well as spam emails, malicious websites and ALPC Task Scheduler Zero-day exploit,[5] making Gandcrab 5.0.4 ransomware one of the most rampantly growing threats in the past few weeks.

Just as like its previous variants, Gandcrab v5.0.4 virus uses sophisticated encryption algorithm RSA and Salsa20 to encrypt files such as videos, pictures, images, databases documents, and renders them useless. To retrieve access to the data, victims are urged to contact criminals via the TOR browser or a provided email address. The full ransomware note reads the following:

—= GANDCRAB V5.0.4 =—

All your files, documents, photos, databases and other important files are encrypted and have the extension: .OBKBTXTN

The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.

The server with your key is in a closed network TOR. You can get there by the following ways:

| 0. Download Tor browser – hxxps://

| 1. Install Tor browser
| 2. Open Tor Browser
| 3. Open link in TOR browser: hxxp://gandcrabmfe6mnef.onion/bba886b160b8e97e
| 4. Follow the instructions on this page


On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.








As usual, experts recommend avoiding any contact with cybercriminals and taking care of Gandcrab 5.0.4 ransomware removal instead. Hackers should never be trusted as they use clever social engineering to trick people into paying money. Malware authors can simply ignore you after the ransom is paid (they usually demand between $800 and $2400 in Bitcoin or Dash), so you will end up losing both – files and money. Thus, do not risk being a victim of a scam, as such scenario is highly plausible.

To remove Gandcrab 5.0.4 ransomware, you should download and install comprehensive security software, bring it up to date, enter Safe Mode with Networking and perform a full system scan. This should disable the virus temporary and allow the security program to operate correctly.

Only after Gandcrab v5.0.4 elimination, you should attempt file recovery. The latest variant of GandCrab is already decryptable. The tools that you can use are provided in our recovery guide below. Unfortunately, we have been informed that for some victims the decryption tool fails to work. In this case, try third-party methods.

GandCrab 5.0.4 virusGandCrab 5.0.4 is a ransomware infection that uses exploit kits, spam emails, malicious sites, and other propagation techniques to infiltrate the machines of thousands of users

Patch your software on time and be aware of spam email campaigns

Since the latest variant utilizes Fallout exploit kit, as well as vulnerability, make sure you patch your software regularly. Security updates are vital for any machine, as it blocks malicious payloads bypassing bugs inside the software. It is equally important to update security software on a regular basis, as detection databases are updated daily.

Nevertheless, be aware that new malware strings are emerging every day, so staying alert while browsing the internet and opening spam emails are vital to virtual safety. We recommend you stay away from the torrent, file-sharing, gambling, porn,[6] and similar insecure sites. Likewise, opening email attachments from an unknown source is also a bad idea. If you are not sure if the email is legitimate, contact the company that is allegedly sending it, and confirm that email is not fake. Also, scanning the attached file with security software is recommended.

GandCrab 5.0.4 virus elimination and file recovery

Despite crooks’ warnings, you should not delay Gandcrab 5.0.4 ransomware removal. The malware might compromise the safety of the machine, and allow other dangerous infections to slip through. Therefore, if you still do not have security software, download and install ReimageIntego or SpyHunter 5Combo Cleaner and run a full system scan. In some cases, the cyber threat might block anti-malware software, so entering Safe Mode with Networking might be a way out.

Only after you remove Gandcrab 5.0.4 virus, you can attempt file recovery. If you have backups available – do not connect the external device to the infected machine, of all your backups will be ruined and encrypted as well! If you do not have backups, follow our guide below to try alternative methods designed to help victims decrypt Gandcrab 5.0.4. There is also an official tool from Bitdefender that you can use to recover encrypted data. It is provided in the link below.

do it now!
Reimage Happiness
Intego Happiness
Compatible with Microsoft Windows Compatible with macOS
What to do if failed?
If you failed to fix virus damage using Reimage Intego, submit a question to our support team and provide as much details as possible.
Reimage Intego has a free limited scanner. Reimage Intego offers more through scan when you purchase its full version. When free scanner detects issues, you can fix them using free manual repairs or you can decide to purchase the full version in order to fix them automatically.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage, try running SpyHunter 5.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Intego, try running Combo Cleaner.

Getting rid of Gandcrab 5.0.4 virus. Follow these steps

Manual removal using Safe Mode

To remove Gandcrab v5.0.4 ransomware safely, enter Safe Mode with Networking

Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.

Step 1. Access Safe Mode with Networking

Manual malware removal should be best performed in the Safe Mode environment. 

Windows 7 / Vista / XP
  1. Click Start > Shutdown > Restart > OK.
  2. When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. – it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
  3. Select Safe Mode with Networking from the list. Windows 7/XP
Windows 10 / Windows 8
  1. Right-click on Start button and select Settings.
  2. Scroll down to pick Update & Security.
    Update and security
  3. On the left side of the window, pick Recovery.
  4. Now scroll down to find Advanced Startup section.
  5. Click Restart now.
  6. Select Troubleshoot. Choose an option
  7. Go to Advanced options. Advanced options
  8. Select Startup Settings. Startup settings
  9. Press Restart.
  10. Now press 5 or click 5) Enable Safe Mode with Networking. Enable safe mode

Step 2. Shut down suspicious processes

Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Click on More details.
    Open task manager
  3. Scroll down to Background processes section, and look for anything suspicious.
  4. Right-click and select Open file location.
    Open file location
  5. Go back to the process, right-click and pick End Task.
    End task
  6. Delete the contents of the malicious folder.

Step 3. Check program Startup

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Go to Startup tab.
  3. Right-click on the suspicious program and pick Disable.

Step 4. Delete virus files

Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:

  1. Type in Disk Cleanup in Windows search and press Enter.
    Disk cleanup
  2. Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
  3. Scroll through the Files to delete list and select the following:

    Temporary Internet Files
    Recycle Bin
    Temporary files

  4. Pick Clean up system files.
    Delete temp files
  5. You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):


After you are finished, reboot the PC in normal mode.

Remove Gandcrab 5.0.4 using System Restore

You can also disable the virus using System Restore:

  • Step 1: Reboot your computer to Safe Mode with Command Prompt
    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of Gandcrab 5.0.4. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with ReimageIntego and make sure that Gandcrab 5.0.4 removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove Gandcrab 5.0.4 from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by security experts.

If your files are encrypted by Gandcrab 5.0.4, you can use several methods to restore them:

Data Recovery Pro can help you with file decryption

Data Recovery Pro was originally designed to help users who accidentally deleted or otherwise corrupted personal files. Nevertheless, this application was also useful in some cases of ransomware infections.

  • Download Data Recovery Pro;
  • Follow the steps of Data Recovery Setup and install the program on your computer;
  • Launch it and scan your computer for files encrypted by Gandcrab 5.0.4 ransomware;
  • Restore them.

Make use of Windows Previous Version feature

This method allows you to recover files one-by-one, so retrieving large amounts of data might be impossible

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

ShadowExplorer can utilize Shadow Volume Copies to recover files encrypted by Gandcrab 5.0.4 ransomware

If the virus failed to remove Shadow Volume Copies, this tool will recover all your files.

  • Download Shadow Explorer (;
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

The official GanCrab 5.0.4 decryptor is already available

Recently, Bitdefender released an official tool to help the affected users recover encrypted data. You can download it here.

Another tool was released by another security expert and can be downloaded from here. While the tool is initially created for all versions up to 5.0.3, it might work for 5.0.4 in some cases.

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Gandcrab 5.0.4 and other ransomwares, use a reputable anti-spyware, such as ReimageIntego, SpyHunter 5Combo Cleaner or Malwarebytes

How to prevent from getting ransomware

Do not let government spy on you

The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices. Avoid any unwanted government tracking or spying by going totally anonymous on the internet. 

You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using Private Internet Access VPN.

Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.

Backup files for the later use, in case of the malware attack

Computer users can suffer from data losses due to cyber infections or their own faulty doings. Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact – you can set this process to be performed automatically.

When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use Data Recovery Pro for the data restoration process.

About the author
Lucia Danes
Lucia Danes - Virus researcher

If this free guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Lucia Danes
About the company Esolutions

Removal guides in other languages