Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.fcv information

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.fcv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.fcv virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Trojan-Ransom.Win32.GandCrypt.fcv?


File Info:

crc32: 2FC3F5DB
md5: 93ad328f216fa50b356a37feca83325c
name: 93AD328F216FA50B356A37FECA83325C.mlw
sha1: b624955639bebb465408248867cff4e187fda441
sha256: d2225a9ec3a9d62ddbb3ccfc958a94287e1fca745377e26b22a9a4205e8127f5
sha512: 1e0f66ea8f569207a8fd875b64694d9d66745abd2c631da83f875721ae758c90bad0c09d13b59ab7df3e13abeb0f3afbc47105a5f94da5cbb4adf74d61b9af4f
ssdeep: 12288:yUKUUsbupyqtMjjnv80y+i0VQzDUHzaBRRDOn:yU98p5cCzDUuSn
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9alch. All rights reserved.
Assembly Version: 6.4.68.8
InternalName: Ancient
FileVersion: 6.4.68.8
CompanyName: alch
PrivateBuild: 6.4.68.8
LegalTrademarks: Copyright xa9alch. All rights reserved.
Comments: Findrecent Ids Combo Attitudes Flex Player
ProductName: Ancient
Languages: English
ProductVersion: 6.4.68.8
FileDescription: Findrecent Ids Combo Attitudes Flex Player
OriginalFilename: Ancient
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.GandCrypt.fcv also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00536ba11 )
LionicTrojan.Win32.GandCrypt.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.GandCrab
MalwarebytesRansom.GandCrab
ZillyaTrojan.GandCrypt.Win32.724
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.40496383
K7GWTrojan ( 00536ba11 )
Cybereasonmalicious.f216fa
CyrenW32/Filecoder.UEAO-6888
SymantecDownloader
ESET-NOD32Win32/Filecoder.GandCrab.D
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.GandCrypt.fcv
AlibabaRansom:Win32/GandCrypt.b8824c8e
NANO-AntivirusTrojan.Win32.GandCrypt.fibzje
ViRobotTrojan.Win32.GandCrab.733184[UPX]
MicroWorld-eScanTrojan.GenericKD.40496383
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKD.40496383
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34170.BmKfaaxtYDdi
VIPREWin32.Malware!Drop
TrendMicroRansom_GANDCRAB.THOIBEAH
FireEyeGeneric.mg.93ad328f216fa50b
EmsisoftTrojan.GenericKD.40496383 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GandCrypt.mx
WebrootW32.Ransom.Gancrab
AviraTR/FileCoder.hgwjd
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D269ECFF
GDataWin32.Trojan.Agent.PLWC1T
AhnLab-V3Trojan/Win32.FileCoder.C2724205
VBA32TrojanRansom.GandCrypt
TrendMicro-HouseCallRansom_GANDCRAB.THOIBEAH
YandexTrojan.GandCrypt!IruVUKlkL98
IkarusTrojan-Ransom.Crypter
MaxSecureTrojan.Malware.79536539.susgen
FortinetW32/Filecoder_GandCrab.D!tr.ransom
PandaTrj/WLT.D

How to remove Trojan-Ransom.Win32.GandCrypt.fcv?

Trojan-Ransom.Win32.GandCrypt.fcv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment