Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

Trojan-Ransom.Win32.GandCrypt.erw removal instruction

Published Sep 13, 2021 Ransom category 3 min read
Report context

What to verify before removal

Trojan-Ransom.Win32.GandCrypt.erw removal instruction should be handled as a recovery-sensitive report, not as a routine deletion task. Before removing files, isolate the affected system and compare the detection with the notes below so encrypted data, restore points, and backups are not damaged.

The technical section is meant to connect the detection name with observable evidence such as file-encryption activity, ransom notes, renamed documents, and unexpected recovery blockers. Compare the identifiers here with the local file before deleting anything, then use the cleanup workflow to scan, quarantine, and verify the system state.

  • Confirm the detection name matches Trojan-Ransom.Win32.GandCrypt.erw removal instruction before removing related files.
  • Review the report for file-encryption activity, ransom notes, renamed documents, and unexpected recovery blockers so the cleanup is based on observed behavior, not only the label.
  • Disconnect the machine from the network before recovery work and avoid deleting encrypted samples until backups are checked.

The Trojan-Ransom.Win32.GandCrypt.erw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan-Ransom.Win32.GandCrypt.erw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (7 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.billerimpex.com
billerimpex.com
www.macartegrise.eu
www.poketeg.com
perovaphoto.ru
asl-company.ru
www.fabbfoundation.gm
www.perfectfunnelblueprint.com
www.wash-wear.com
pp-panda74.ru
cevent.net
bellytobabyphotographyseattle.com
alem.be
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
boatshowradio.com
dna-cp.com
acbt.fr
r3.o.lencr.org
wpakademi.com
www.cakav.hu
www.mimid.cz
6chen.cn
goodapd.website
oceanlinen.com
tommarmores.com.br
nesten.dk
zaeba.co.uk
www.n2plus.co.th
koloritplus.ru
h5s.vn
marketisleri.com
www.toflyaviacao.com.br
www.rment.in
www.lagouttedelixir.com
www.krishnagrp.com
big-game-fishing-croatia.hr
ocsp.digicert.com
mauricionacif.com
www.ismcrossconnect.com
aurumwedding.ru
test.theveeview.com
relectrica.com.mx

How to determine Trojan-Ransom.Win32.GandCrypt.erw?


File Info:

crc32: 27F113A2
md5: 980e9d820d70b12676717ec6cc1090eb
name: 980E9D820D70B12676717EC6CC1090EB.mlw
sha1: 3b0da193f64b797f32a8142a9c32ab6f4df14bdb
sha256: d21c74d73792bcc544750fe0a70685926322e4da2682c2781ecc57de6e15c4ec
sha512: ecbb4721918ec95ea7990679346315f7dcf20dc72f80d6e9a9b5b8ca2b484194e4276d4524257c4f893adacb510db90f31c6c539507586853c29e2f58638fe07
ssdeep: 3072:o89lh5lWQGRiP+KEbWRcyS40sxOWkHSNBa/PoDqKRDC9FMFA6:HnG+kA0Ay6OgDqKBC9F2A6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: tgabhryj.exe
FileVersion: 4.5.7

Trojan-Ransom.Win32.GandCrypt.erw also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Trojan ( 0053c2831 )
Lionic Trojan.Win32.GandCrypt.4!c
Elastic malicious (high confidence)
DrWeb Trojan.Encoder.25976
ALYac Trojan.BRMon.Gen.4
Malwarebytes Trojan.MalPack
Zillya Trojan.GandCrypt.Win32.652
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Trojan.BRMon.Gen.4
K7GW Trojan ( 0053c2831 )
Cybereason malicious.20d70b
Cyren W32/Kryptik.ID.gen!Eldorado
Symantec Packed.Generic.525
ESET-NOD32 a variant of Win32/Kryptik.GKPT
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan-Ransom.Win32.GandCrypt.erw
Alibaba Ransom:Win32/GandCrypt.92ff2eae
NANO-Antivirus Trojan.Win32.GandCrypt.fhngbg
ViRobot Trojan.Win32.R.Agent.228352.AC
MicroWorld-eScan Trojan.BRMon.Gen.4
Tencent Win32.Trojan.Gandcrypt.Hrow
Ad-Aware Trojan.BRMon.Gen.4
Sophos Mal/Generic-R + Mal/GandCrab-B
Comodo Malware@#103kt6r20li33
BitDefenderTheta Gen:NN.ZexaF.34142.nu0@am9gJCcG
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
FireEye Generic.mg.980e9d820d70b126
Emsisoft Trojan.BRMon.Gen.4 (B)
SentinelOne Static AI – Malicious PE
Jiangmin Trojan.GandCrypt.lz
Avira HEUR/AGEN.1106537
Antiy-AVL Trojan/Generic.ASMalwS.2803D26
Microsoft VirTool:Win32/CeeInject.AAG!bit
Arcabit Trojan.BRMon.Gen.4
ZoneAlarm Trojan-Ransom.Win32.GandCrypt.erw
GData Win32.Trojan-Ransom.GandCrab.U
AhnLab-V3 Win-Trojan/MalPe34.Suspicious.X2029
Acronis suspicious
VBA32 BScope.Trojan.Fuerboos
MAX malware (ai score=100)
Rising Trojan.Generic@ML.100 (RDML:78SqL2hLmIqzdtKV1PypAA)
Yandex Trojan.GenAsa!+9WQtD1UcSg
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.CNAR!tr
Panda Trj/GdSda.A

How to remove Trojan-Ransom.Win32.GandCrypt.erw?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.