<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>GandCrab &#8211; AnonyViet &#8211; English Version</title>
	<atom:link href="https://en.anonyviet.com/tag/gandcrab/feed/" rel="self" type="application/rss+xml" />
	<link>https://en.anonyviet.com</link>
	<description>The most popular website for sharing information technology, computer networks, and security knowledge. Stay up to date with the hottest news and tips</description>
	<lastBuildDate>Thu, 02 Feb 2023 10:18:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://en.anonyviet.com/wp-content/uploads/2023/01/cropped-ico-logo-75x75-1.png</url>
	<title>GandCrab &#8211; AnonyViet &#8211; English Version</title>
	<link>https://en.anonyviet.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How to decrypt Ransomware Ransomware Virus GandCrab v1 &#8211; v5.2</title>
		<link>https://en.anonyviet.com/how-to-decrypt-ransomware-ransomware-virus-gandcrab-v1-v5-2/</link>
					<comments>https://en.anonyviet.com/how-to-decrypt-ransomware-ransomware-virus-gandcrab-v1-v5-2/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Thu, 02 Feb 2023 10:18:08 +0000</pubDate>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[decrypt]]></category>
		<category><![CDATA[GandCrab]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[v5.2]]></category>
		<category><![CDATA[virus]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=8332</guid>

					<description><![CDATA[After the fierce attack from WannaCry Ransomware GandCrab is currently raging in Vietnam and around the world. Companies and businesses are having a lot of headaches because all data is encrypted and there is no decryption. The IT Managers only have to submit A4 papers to apply for a job. Most ransomware infects via Remote [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>After the fierce attack from <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fdownload-ransomware-wannacry-virus-tong-tien-manh-nhat-2017%2F" rel="noopener noreferrer" class="local-link">WannaCry </a>Ransomware GandCrab is currently raging in Vietnam and around the world.  Companies and businesses are having a lot of headaches because all data is encrypted and there is no decryption.  The IT Managers only have to submit A4 papers to apply for a job.  Most ransomware infects via Remote Desktop by detecting Passwords.  Even if you have the latest anti-virus software installed, you will still be infected as usual.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The owner of the GandCrab recently announced an end to the Ransomware-as-a-Service (RaaS) activities of a criminal hacker group associated with organized crime that extort more than $2 billion. from the victims.</p>
<p>Facing that situation, Bitdefender has just announced the GandCrab Version 5.2 decryption tool.  This is the latest Version that can decrypt all versions of Ransomware GandCrab.</p>
<h2 id="ftoc-phien-ban-ransomware-gandcrab-duoc-giai-ma" class="ftwp-heading">GandCrab Ransomware Version Decrypted</h2>
<p style="text-align: justify;">The good news for computer users who are victims of GandCrab, the new decryption tool released by BitDefender, can now unlock files encrypted by the latest versions of the GandCrab v5.2 Ransomware, as well as for older GandCrab ransomware versions.  An updated version of the GandCrab ransomware decryption tool could allow millions of affected users to unlock their encrypted files for free without paying a ransom to cybercriminals.</p>
<p>The list below includes decoding variants of the GandCrab Ransomware.  You need to determine the exact file extension to know which Version you are encrypted in.</p>
</p>
<table width="835">
<tbody>
<tr>
<td width="128">Version 1:</td>
<td width="182">extension: .GDCB.</td>
<td width="525">Start with —= GANDCRAB ==, ………….  extension: .GDCB</td>
</tr>
<tr>
<td>Version 2:</td>
<td>extension: .GDCB.</td>
<td>Start with —= GANDCRAB ==, ………….  extension: .GDCB</td>
</tr>
<tr>
<td>Version 3:</td>
<td>extension: .CRAB.</td>
<td>Start with —= GANDCRAB V3 == ………….. extension: .CRAB</td>
</tr>
<tr>
<td>Version 4:</td>
<td>extension: .KRAB.</td>
<td>Start with —= GANDCRAB V4 == ………….. extension: .KRAB</td>
</tr>
<tr>
<td>Version 5:</td>
<td>extension: .([A-Z]+).</td>
<td>Start with —= GANDCRAB V5.0 == ………….  extension: .UKCZA</td>
</tr>
<tr>
<td>Version 5.0.1:</td>
<td>extension: .([A-Z]+).</td>
<td>Start with —= GANDCRAB V5.0.1 == … ….  extension: .YIAQDG</td>
</tr>
<tr>
<td>Version 5.0.2:</td>
<td>extension: .([A-Z]+).</td>
<td>Start with —= GANDCRAB V5.0.2 == ….  extension: .CQXGPMKNR</td>
</tr>
<tr>
<td>Version 5.0.3:</td>
<td>extension: .([A-Z]+).</td>
<td>Start with —= GANDCRAB V5.0.3 == … ….  extension: .HHFEHIOL</td>
</tr>
<tr>
<td>Version 5.0.3:</td>
<td>extension: .([A-Z]+).</td>
<td>Start with —= GANDCRAB V5.0.4 == … ….  extension: .BYACZCZI</td>
</tr>
<tr>
<td>Version 5.0.5:</td>
<td>extension: .([A-Z]+).</td>
<td>Start with —= GANDCRAB V5.0.5 == … ….  extension: .KZZXVWMLI</td>
</tr>
<tr>
<td>Version 5.0.5:</td>
<td>extension: .([A-Z]+).</td>
<td>Start with —= GANDCRAB V5.1 == … ….  extension: .IJDHRQJD</td>
</tr>
<tr>
<td>Version 5.0.6 – 5.2</td>
<td>extension: .([A-Z]+).</td>
<td>Start with —= GANDCRAB V5.1 == … ….  extension: .IJDHRQJD</td>
</tr>
</tbody>
</table>
<h3 id="ftoc-luu-y-khi-su-dung-tool-giai-ma-virus-ransomware-gandcrab" class="ftwp-heading">Note when using GANDCRAB Ransomware Virus Decryption Tool</h3>
<p><strong>Computer infected with Virus must connect to the Internet.</strong> The decryption servers will attempt to reply to the sent ID with a possibly valid RSA-2048 private key.  Only if this step is successful, the GandCrab Ransomware decryption process will continue.</p>
<p><strong>Ransom notice.</strong> For this recovery solution to work, you must have at least (1) copy of the ransom notice on your PC.  Note the ransom is required to recover the decryption key, as it is used to compute the unique decryption key for your data.  Friend <strong>impossible</strong> run the cleanup utility to detect and remove the ransom note before executing this tool.</p>
<h2 id="ftoc-cach-giai-ma-virus-tong-tien-ransomware-gandcrab-5-2" class="ftwp-heading">How to decode Ransomware Ransomware Virus GandCrab 5.2</h2>
<p><strong>Step 1:</strong> Download <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Flabs.bitdefender.com%2Fwp-content%2Fuploads%2Fdownloads%2Fgandcrab-removal-tool-v1-v4-v5%2F" rel="noopener noreferrer external nofollow" class="ext-link" onclick="this.target='_blank';">Ransomware decryption tool GandCrab</a> to your computer.Note that this tool requires an active internet connection.  Without the Internet, the decryption process will not continue.</p>
<p><strong>Step 2:</strong> Run BDGandCrabDecryptor.exe.</p>
<p><strong>Step 3:</strong> Agree to the terms and conditions.</p>
<p><strong>Step 4:</strong> Select “Scan Entire System” if you want to search all encrypted data.  Or just add the path to the encrypted file.  You should choose &#8220;<strong>Backup files”. </strong>Then choose <strong>Scan</strong>.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2019%2F02%2Fbit.jpeg" rel="noopener" class="local-link"><img post-id="8332" fifu-featured="1" fetchpriority="high" decoding="async" class="aligncenter wp-image-13871 size-full" src="https://anonyviet.com/wp-content/uploads/2019/02/bit.jpeg" alt="How to decrypt Ransomware Ransomware Virus GandCrab v1 &#8211; v5.2" title="How to decrypt Ransomware Ransomware Virus GandCrab v1 &#8211; v5.2" width="572" height="387" srcset="https://anonyviet.com/wp-content/uploads/2019/02/bit.jpeg 572w, https://anonyviet.com/wp-content/uploads/2019/02/bit-300x203.jpeg 300w" sizes="(max-width: 572px) 100vw, 572px" title="How to decrypt Ransomware Ransomware Virus GandCrab v1 - v5.2 6"/></a></p>
<p>Regardless of whether you choose Backup File or not, the decryption tool will attempt to decrypt the first 5 files in the provided path and will <strong>ARE NOT</strong> continue if decryption fails.</p>
<p><strong>Step 5:</strong> Now, the data has been decrypted.  If you have selected the Backup File option, you will see both the encrypted file and the decrypted file.  You should verify whether the decrypted data can be opened, by opening the data.</p>
<p>In addition, you can refer to the decryption tools of other Ransomeware at:  <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.nomoreransom.org%2Fen%2Fdecryption-tools.html" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">https://www.nomoreransom.org/en/decryption-tools.html</a></p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;13870&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-decrypt-ransomware-ransomware-virus-gandcrab-v1-v5-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2019/02/bit.jpeg" medium="image"></media:content>
            	</item>
	</channel>
</rss>
