Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.fbh removal instruction

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.fbh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.fbh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.GandCrypt.fbh?


File Info:

crc32: 6A661766
md5: ba9589c1d550668e89cbd443bef7e398
name: BA9589C1D550668E89CBD443BEF7E398.mlw
sha1: 2bb35f219883b59744d6861907b94e50f2af05d0
sha256: 6c0dbde81a7225d5820ecc64d52427cfd0331551b39a4a9edba8a7b126b5f9ac
sha512: e4b7da3233a2a4b944f5ffe96d0eb549d5ee24d7a5c70e6a689c324785e2ee7fd1d2ffb283aa45c6d825e7df3a86dc805e04a58f5cd11fc85ea1585e21d6a46b
ssdeep: 3072:VvsBVaR38ib9Wy7EHkybCzp7W5/WrO+ZsGBu9PMBN8Dx:V8VK38yLhygMmmGBA8ex
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.GandCrypt.fbh also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26344
CynetMalicious (score: 100)
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/GandCrypt.002002
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.1d5506
CyrenW32/Kryptik.II.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKVD
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.GandCrypt.fbh
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.GandCrypt.fhwktp
ViRobotTrojan.Win32.R.Agent.180736.E
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentMalware.Win32.Gencirc.10cc6364
Ad-AwareTrojan.BRMon.Gen.4
SophosML/PE-A + Mal/GandCrab-B
ComodoTrojWare.Win32.Ransom.GandCrab.AD@7vdpwf
BitDefenderThetaGen:NN.ZexaF.34684.luW@auAsGMhG
TrendMicroTrojanSpy.Win32.CLIPBANKER.SMB
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.ba9589c1d550668e
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Coins.bkp
AviraHEUR/AGEN.1121541
MicrosoftTrojan:Win32/Gandcrab.PVD!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataTrojan.BRMon.Gen.4
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeeTrojan-FPYT!BA9589C1D550
MAXmalware (ai score=89)
VBA32TrojanRansom.GandCrypt
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.CLIPBANKER.SMB
RisingTrojan.Kryptik!1.B418 (CLOUD)
YandexTrojan.GenAsa!7QuuuwW6Cqo
IkarusTrojan.Crypt
FortinetW32/Kryptik.GKTH!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.GandCrypt.fbh?

Trojan-Ransom.Win32.GandCrypt.fbh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment