Malware

Troj/Gandcra-CP removal instruction

Malware Removal

The Troj/Gandcra-CP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Gandcra-CP virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Troj/Gandcra-CP?


File Info:

name: 89D96EEE2079A54151B1.mlw
path: /opt/CAPEv2/storage/binaries/6603447e99d35e930df38ab47a5dd7303fbdaed01317a698118a0f192a15ad39
crc32: 6C121DD6
md5: 89d96eee2079a54151b1e457cca377ec
sha1: 0be6f79116dd2abf130e80197acebcb128e81460
sha256: 6603447e99d35e930df38ab47a5dd7303fbdaed01317a698118a0f192a15ad39
sha512: bb6c9f79724452e4b00e309b62b05800c5d3b276b0b51389a5e73a2b8bd70b1b82470f4491b82323c39b30da7dab46d31bdc3e8cd0dac46a542017ea7495eb71
ssdeep: 6144:ko+k6sXkPV9WBtpypFBK4Tu/6u9qXZqN8ebeja9ZoeG7UJDGLwrvv3+sHE1:brWcDkpFBK4Tui48eqj/7+GSHvy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A94E02571C4C032E9A711314BD9D7A6683ABDB2AB2254C377E46B2E6F713E1C636307
sha3_384: ed4de1d6ac1bdbf8b198e2ac6169227a0bb691e20d104e211bb99a99af3f10df786537aa3a4420f6a8b6538cc276b8fd
ep_bytes: e8d7650000e989feffff8bff558bec5d
timestamp: 2007-11-05 10:30:10

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 12.0.4518.1014
InternalName: WinWord
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Troj/Gandcra-CP also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.21809
MicroWorld-eScanTrojan.GenericKDZ.94750
ClamAVWin.Malware.Ulise-9768992-0
FireEyeTrojan.GenericKDZ.94750
CAT-QuickHealTrojan.MauvaiseRI.S5243370
ALYacTrojan.GenericKDZ.94750
Cylanceunsafe
ZillyaDropper.Agent.Win32.158548
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_240010b.None
K7GWTrojan ( 0049f4651 )
K7AntiVirusTrojan ( 0049f4651 )
CyrenW32/Agent.AOF.gen!Eldorado
SymantecTrojan.Gen.2
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKDZ.94750
AvastWin32:Agent-AYZG [Cryp]
TencentBackdoor.Win32.Salgorea.za
EmsisoftTrojan.GenericKDZ.94750 (B)
VIPRETrojan.GenericKDZ.94750
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosTroj/Gandcra-CP
IkarusTrojan.Win32.Salgorea
GDataWin32.Trojan.Salgorea.B
JiangminTrojan/Generic.azstc
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Agent.QGO@57p1tw
ArcabitTrojan.Generic.D1721E
SUPERAntiSpywareTrojan.Agent/Gen-Agent
MicrosoftTrojan:Win32/Salgorea.A!MTB
GoogleDetected
AhnLab-V3Malware/Win32.Generic.R369404
Acronissuspicious
McAfeeGenericRXCD-OV!89D96EEE2079
TACHYONTrojan/W32.Agent.419332.C
MalwarebytesSalgorea.Trojan.Dropper.DDS
PandaTrj/CI.A
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
YandexTrojan.Agent!6eYHPom187s
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Salgorea.A!dam
AVGWin32:Agent-AYZG [Cryp]
Cybereasonmalicious.116dd2
DeepInstinctMALICIOUS

How to remove Troj/Gandcra-CP?

Troj/Gandcra-CP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment