Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.ann removal instruction

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.ann is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.ann virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Trojan-Ransom.Win32.GandCrypt.ann?


File Info:

crc32: CEBE3198
md5: ac9f6d7c71fab6f44b3ab941c2c15058
name: AC9F6D7C71FAB6F44B3AB941C2C15058.mlw
sha1: baf10033ac09f85de711750197da920c87e38647
sha256: 4f8b38f4c6b369081686023e86f9ed89bf66e9b727cd219c7e92fb2d037ea4aa
sha512: 8d60850e91a597a9dcb85f689a657c14acb31679926d65dca4091e97ab574c89eaaf11f2b9228a309f717edad292b823dd08e4708e33b48d3b7c6731091f6f25
ssdeep: 3072:PVjHQC2mCjuTZgPTPhLjdRxXebhNBTG8zdR1UOalRGKTOWUox0FVuzGOp1RvVYbZ:zO7PhHkND1p0RGJ1oyQzGmvVYb3bKop
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0789 0x04b1

Trojan-Ransom.Win32.GandCrypt.ann also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.ac9f6d7c71fab6f4
CAT-QuickHealTrojan.Chapak.ZZ5
McAfeeGenericRXFJ-RT!AC9F6D7C71FA
CylanceUnsafe
VIPREWin32.Malware!Drop
AegisLabTrojan.Win32.GandCrypt.j!c
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 0053305e1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 00526c7b1 )
Cybereasonmalicious.c71fab
CyrenW32/S-8ce49c37!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Gandcrab-6552923-4
KasperskyTrojan-Ransom.Win32.GandCrypt.ann
NANO-AntivirusTrojan.Win32.Stealer.fbtdni
ViRobotTrojan.Win32.GandCrab.Gen.A
RisingTrojan.Kryptik!1.B1E3 (CLOUD)
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
ComodoTrojWare.Win32.Chapak.GG@7ne4ou
F-SecureTrojan.TR/AD.GandCrab.kaouc
DrWebTrojan.PWS.Stealer.23758
ZillyaTrojan.GandCrypt.Win32.217
TrendMicroRansom.Win32.GANDCRAB.SMLA.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
MaxSecureRansomeware.GandCrypt.Gen
SophosMal/Generic-R + Mal/Agent-AUL
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.Banker.TinyNuke.er
AviraTR/AD.GandCrab.kaouc
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/GandCrab.AS
ArcabitTrojan.Ransom.GandCrab.Gen.2
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.ann
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
VBA32BScope.TrojanRansom.GandCrypt
ALYacTrojan.Ransom.GandCrab.Gen.2
TACHYONRansom/W32.GandCrab
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
ZonerTrojan.Win32.68332
ESET-NOD32Win32/Filecoder.GandCrab.B
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMLA.hp
TencentMalware.Win32.Gencirc.10b54aa5
YandexTrojan.GandCrypt!fCcHoarrqC8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.BFJ!tr
BitDefenderThetaGen:NN.ZexaF.34590.pyX@auNh!Qgi
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.222

How to remove Trojan-Ransom.Win32.GandCrypt.ann?

Trojan-Ransom.Win32.GandCrypt.ann removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment