Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.feh removal

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.feh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.feh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.GandCrypt.feh?


File Info:

crc32: 20E30629
md5: ad515436b79ab1b868782f3909630b77
name: AD515436B79AB1B868782F3909630B77.mlw
sha1: 31516af1a3a6a16be05ec70ee9b5738a514a37f3
sha256: 2e49776e0cbc8a8ba8e6740d4462616ef647e37df9cfae37734b97b6cb79af46
sha512: 2ea9c7bed022e1fe3cd0ca87db66699c6be9a2dade063f1b61e3a79fb7af67cd99904f4697f06765ebd65800c004e19b4d2b15e106373fd1ceea19daff1d0b3d
ssdeep: 3072:CfCBRUk24+Jy6EOYoRzl722Oo00wqCCR6e/47rYqOvV:NBR5bW5DkSR6P7rYqOv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-Ransom.Win32.GandCrypt.feh also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053cd131 )
LionicTrojan.Win32.GandCrypt.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
CynetMalicious (score: 100)
CAT-QuickHealRansom.GandCrab.S3886332
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.799
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/GandCrypt.7cb134eb
K7GWTrojan ( 0053cd131 )
Cybereasonmalicious.6b79ab
CyrenW32/Kryptik.KN.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKXZ
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Midie-7060941-0
KasperskyTrojan-Ransom.Win32.GandCrypt.feh
BitDefenderTrojan.Ransomware.GenericKDS.31225990
NANO-AntivirusTrojan.Win32.GandCrypt.fichcy
ViRobotTrojan.Win32.R.Agent.169984.AB
MicroWorld-eScanTrojan.Ransomware.GenericKDS.31225990
TencentWin32.Trojan.Gandcrypt.Lohl
Ad-AwareTrojan.Ransomware.GenericKDS.31225990
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanSpy.Ursnif.EM@7vyz23
BitDefenderThetaGen:NN.ZexaF.34170.kuW@a0x88BoG
TrendMicroTrojanSpy.Win32.GUILDMA.SMAL
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.ad515436b79ab1b8
EmsisoftTrojan.Ransomware.GenericKDS.31225990 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.ne
AviraHEUR/AGEN.1106537
Antiy-AVLTrojan/Generic.ASMalwS.2817BA5
MicrosoftVirTool:Win32/CeeInject.UQ!bit
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.U
TACHYONRansom/W32.GandCrab.169984
AhnLab-V3Win-Trojan/MalPe36.Suspicious.X2037
Acronissuspicious
McAfeeTrojan-FQPW!AD515436B79A
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.GUILDMA.SMAL
RisingTrojan.Kryptik!1.B423 (CLASSIC)
YandexTrojan.GenAsa!/RLvJTIaHbY
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.GMSM!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.GandCrypt.feh?

Trojan-Ransom.Win32.GandCrypt.feh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment