Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.exp (file analysis)

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.exp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.exp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.GandCrypt.exp?


File Info:

crc32: EE225A18
md5: 86f85e74b985a829035e350b5c8c9874
name: 86F85E74B985A829035E350B5C8C9874.mlw
sha1: 3baa166e83727dcad9f2405b31cc0dc442fd06b9
sha256: 8b5d5c0bcdb30772c64990f0280b68fd89a36d61919ef23107010952b256ab96
sha512: e582d7b39fc50efaba03215f8cdf3080b83b37e99aa40f3e1ff5ca515322486c3217f2e13842feeb75ac0cd77d3d263f145729a26c6ce76950b4ec48b2cd5376
ssdeep: 3072:RXgt1Qb80e4l+SwC5zYqTS1nAJhCkIJT6Fl34IL5+3OE+:Fi1Qb8+fYMSBAETQuIc33+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: dfogdofgb.exe
FileVersion: 1.0.0.2
Translation: 0x0809 0x04b0

Trojan-Ransom.Win32.GandCrypt.exp also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
CynetMalicious (score: 100)
McAfeePacked-FLX!86F85E74B985
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.879
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/GandCrypt.002002
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4b985a
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKUD
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan-Ransom.Win32.GandCrypt.exp
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.GandCrypt.fhslan
ViRobotTrojan.Win32.R.Agent.170496
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentWin32.Trojan.Gandcrypt.Edoa
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-R + Mal/GandCrab-B
ComodoTrojWare.Win32.TrojanSpy.Ursnif.EM@7vyz23
BitDefenderThetaGen:NN.ZexaF.34670.ku0@amsIV5cG
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.PUPXFM.cc
FireEyeGeneric.mg.86f85e74b985a829
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Coins.bks
AviraHEUR/AGEN.1106537
MicrosoftTrojan:Win32/Predator!ml
GDataWin32.Trojan-Ransom.GandCrab.N
AhnLab-V3Win-Trojan/MalPe36.Suspicious.X2037
Acronissuspicious
VBA32BScope.TrojanRansom.GandCrypt
MAXmalware (ai score=83)
MalwarebytesRansom.GandCrab
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Vigorf!8.EAEA (CLOUD)
YandexTrojan.GenAsa!Fy2hTHxyMtY
IkarusTrojan.Win32.Ranumbot
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GMSM!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Trojan-Ransom.Win32.GandCrypt.exp?

Trojan-Ransom.Win32.GandCrypt.exp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment