Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.evy removal

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.evy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.evy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.GandCrypt.evy?


File Info:

crc32: D1DA5020
md5: bfc0e64da9f4272e9406d55a127e3bcb
name: BFC0E64DA9F4272E9406D55A127E3BCB.mlw
sha1: bc1ecdd9839bf8fe4323335d813ebdb7abd42aec
sha256: 91817703ed22870872425a4200c949c494a7524cb0bb572902b8196f35c7aba0
sha512: 70bc04fa9b42e260652da2f3eaa358fc7fb5aa2b0a9a3fb873066b97cc7b220bbcc77fd718677ab4f867462fba8fa339afcd295e9d5959766bd1f27a761ed987
ssdeep: 3072:cHMMlbYwVKXqC0leYZNE5wOmEv/KDSwkxl2irBNL+T:cHMMRUceY1Ovv/Kqx8u4T
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.GandCrypt.evy also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053c8861 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
CynetMalicious (score: 100)
ALYacTrojan.Brsecmon.1
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.882
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/GandCrypt.002002
K7GWTrojan ( 0053c8861 )
Cybereasonmalicious.da9f42
CyrenW32/Kryptik.JB.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GKTH
ZonerTrojan.Win32.71930
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Midie-6691267-0
KasperskyTrojan-Ransom.Win32.GandCrypt.evy
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Encoder.fhpjze
MicroWorld-eScanTrojan.Brsecmon.1
TencentMalware.Win32.Gencirc.10cc62b2
Ad-AwareTrojan.Brsecmon.1
SophosML/PE-A + Mal/GandCrab-B
ComodoTrojWare.Win32.PSW.Coins.AF@7vd5q2
BitDefenderThetaGen:NN.ZexaF.34678.luX@aOlo!0hG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.CLIPBANKER.SMB
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.bfc0e64da9f4272e
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Coins.ble
AviraHEUR/AGEN.1121541
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/IcedId.PVS!MTB
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.GandCrypt.gen
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win32.Gandcrab.R237845
Acronissuspicious
McAfeeTrojan-FPYT!BFC0E64DA9F4
VBA32Trojan.Encoder
MalwarebytesMalware.AI.3285251504
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.CLIPBANKER.SMB
RisingTrojan.Vigorf!8.EAEA (CLOUD)
IkarusTrojan.Crypt
FortinetW32/GenKryptik.CNAR!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.IcedID.HwoCEpsA

How to remove Trojan-Ransom.Win32.GandCrypt.evy?

Trojan-Ransom.Win32.GandCrypt.evy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment