Threat Database Ransomware GandCrab.ABW Ransomware

GandCrab.ABW Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 12,643
Threat Level: 100 % (High)
Infected Computers: 10
First Seen: September 17, 2025
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of GandCrab.ABW Ransomware on your system indicates a serious security threat that requires immediate attention. Ransomware is a type of malicious software that encrypts your files and demands payment in exchange for the decryption key. In this report, we will provide you with information about the GandCrab.ABW Ransomware threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is GandCrab.ABW Ransomware?

Ransomware is a type of malware that uses encryption to hold your files hostage. The GandCrab.ABW Ransomware detection suggests that your system has been infected with a variant of ransomware that uses advanced encryption techniques to lock your files. The goal of the attackers is to extort money from you in exchange for the decryption key. It is essential to note that paying the ransom does not guarantee that you will receive the decryption key or that your files will be restored.

How GandCrab.ABW Ransomware Operates

Ransomware typically operates by exploiting vulnerabilities in software or using social engineering tactics to gain access to your system. Once inside, it scans your system for files to encrypt, including documents, images, and videos. The GandCrab.ABW Ransomware may use a combination of encryption algorithms to lock your files, making it difficult to access them without the decryption key. The attackers may also use intimidation tactics, such as displaying fake warnings or countdown timers, to pressure you into paying the ransom.

Symptoms of Infection

The symptoms of a GandCrab.ABW Ransomware infection may include: files being encrypted and inaccessible, ransom demands displayed on your screen, and suspicious network activity. You may also notice that your system is slow or unresponsive, or that certain programs are not functioning correctly. If you suspect that your system has been infected with ransomware, it is essential to act quickly to prevent further damage.

How to Remove GandCrab.ABW Ransomware

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove the GandCrab.ABW Ransomware and any related malware.
  3. Uninstall any suspicious programs or applications that may be associated with the ransomware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan with your anti-malware tool to ensure that the GandCrab.ABW Ransomware has been completely removed.

Conclusion

Removing the GandCrab.ABW Ransomware from your system requires careful attention to detail and a thorough understanding of the malware's operating methods. By following the steps outlined in this report, you can help to ensure that your system is clean and secure. However, prevention is always the best course of action, and it is essential to take proactive measures to protect your system from future ransomware attacks, such as keeping your software up to date, using strong passwords, and being cautious when opening email attachments or clicking on links from unknown sources.

Analysis Report

General information

Family Name: GandCrab.ABW Ransomware
Signature status: No Signature

Known Samples

MD5: 4dcab0a487dcb22162306d416afc4dc2
SHA1: 638f4770ef93d958e1f623c2a4199dbe3422d039
SHA256: 2793898CA191D92BCE0B431174CFD057E555354944D7BC121981E21C6C2ECADA
File Size: 91.65 KB, 91648 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • No Version Info
  • x86

Block Information

Total Blocks: 212
Potentially Malicious Blocks: 193
Whitelisted Blocks: 19
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x 0 1 0 0 0 0 x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • GandCrab.ABW
  • Gandcrab.ABO

Files Modified

File Attributes
c:\windows\syswow64\hkkijpop.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hkkijpop.exe Generic Write,Read Attributes
c:\windows\syswow64\nqigcf32.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Nqigcf32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Hkkijpop.exe

Trending

Most Viewed

Loading...