Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.gjq removal guide

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.gjq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.gjq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.GandCrypt.gjq?


File Info:

crc32: FEE4F69F
md5: aed84257aa3afb9701d5a8309cb2c51b
name: AED84257AA3AFB9701D5A8309CB2C51B.mlw
sha1: c0a0e26c5a6c76ea2cf35842dbf0f06eb6a6b210
sha256: 8ce66648718ae66cf354a8e02534dd20203e1d4fa84b3088a2cc0db8603c3139
sha512: a41fb08f9420caedab08a2d752f89f17e4b8c8ccd7b9e35223cd85de990e7b9ba9e66b20321413ac79f81af8f3ac249c32744fb942664b7c3612c921f40b4985
ssdeep: 3072:Dd5R0YkXVKXUrs96KNgGJGqZx22e65+Io1B9hJtF6IM:m0XU6CzKFe60Xd6
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, tcgisadz
FileVersion: 1.3.6
ProductVersion: 1.0.4.11

Trojan-Ransom.Win32.GandCrypt.gjq also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00543e471 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26667
CynetMalicious (score: 100)
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.1308
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Genasom.ali1000102
K7GWTrojan ( 00543e471 )
Cybereasonmalicious.7aa3af
CyrenW32/Kryptik.NF.gen!Eldorado
SymantecDownloader
ESET-NOD32a variant of Win32/Kryptik.GMPP
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Azorult-7596348-0
KasperskyTrojan-Ransom.Win32.GandCrypt.gjq
BitDefenderTrojan.GenericKDZ.51497
NANO-AntivirusTrojan.Win32.GandCrypt.fkdzbt
ViRobotTrojan.Win32.R.Agent.228352.AM
SUPERAntiSpywareTrojan.Agent/Gen-MalPack
MicroWorld-eScanTrojan.GenericKDZ.51497
TencentWin32.Trojan.Gandcrypt.Lrsi
Ad-AwareTrojan.GenericKDZ.51497
SophosMal/Generic-R + Mal/GandCrab-G
ComodoTrojWare.Win32.Ransom.Gandcrab.GC@7zlhhh
BitDefenderThetaGen:NN.ZexaF.34670.nu0@aSvhD@ji
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionTrojan-FPST!AED84257AA3A
FireEyeGeneric.mg.aed84257aa3afb97
EmsisoftTrojan.GenericKDZ.51497 (B)
JiangminTrojan.PSW.Azorult.bd
AviraHEUR/AGEN.1107191
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/GandCrab.GD!MTB
GDataTrojan.GenericKDZ.51497
AhnLab-V3Trojan/Win32.Gandcrab.R243906
McAfeeTrojan-FPST!AED84257AA3A
MAXmalware (ai score=88)
VBA32BScope.Trojan.Vigorf
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingRansom.GandCrypt!8.F33E (CLOUD)
IkarusTrojan-Ransom.GandCrab
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/Kryptik.GNAQ!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Trojan-Ransom.Win32.GandCrypt.gjq?

Trojan-Ransom.Win32.GandCrypt.gjq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment