Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.gpz removal guide

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.gpz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.gpz virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.GandCrypt.gpz?


File Info:

crc32: F8B9A5BC
md5: 25671f53f3f54b1e795aeb02f1686629
name: 25671F53F3F54B1E795AEB02F1686629.mlw
sha1: 15609842d77ef006674ab8ad8be01c2416740054
sha256: 60faeb48896c332eb549833ddd1dbf45096321e14e48ccaee6ce8aa135b82d02
sha512: 1c5c15da57aa31ca4e7a67296e631c521ea95e85c7398a08ff5a0ea080c059f7fe0433e57e37980fa9f1b7b13e4f022a4da36cab179deb8bb5b77fbbc8c1b2c8
ssdeep: 12288:h/++pwmxtkA9OjR7tV8TbKnwH77pDp/p4:A+pwmnkA9OjR7tVIbKnwu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: flatwise
FileVersion: 76.27.0002
Comments: practice took CENTS BALL LAKE WELCOME
ProductName: PICK'exactly'tone'DANCE'wife'finland<
ProductVersion: 76.27.0002
FileDescription: middle`miss`PURE`string`PLEASANT`GAVE<
OriginalFilename: flatwise.exe

Trojan-Ransom.Win32.GandCrypt.gpz also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00543dea1 )
LionicTrojan.Win32.GandCrypt.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.Jm1@dmK!Icei
CylanceUnsafe
ZillyaAdware.GandCrypt.Win32.20
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GandCrypt.ca01d4e2
K7GWTrojan ( 00543dea1 )
Cybereasonmalicious.3f3f54
CyrenW32/VBKrypt.HM.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EBSO
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Noon-7344212-0
KasperskyTrojan-Ransom.Win32.GandCrypt.gpz
BitDefenderGen:Heur.PonyStealer.Jm1@dmK!Icei
NANO-AntivirusTrojan.Win32.GandCrypt.fkkrkb
MicroWorld-eScanGen:Heur.PonyStealer.Jm1@dmK!Icei
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Heur.PonyStealer.Jm1@dmK!Icei
SophosMal/Generic-R + Mal/FareitVB-V
ComodoMalware@#mx19iah778yr
BitDefenderThetaGen:NN.ZevbaF.34170.Jm1@amK!Icei
TrendMicroTrojanSpy.Win32.FAREIT.SMA.hp
McAfee-GW-EditionFareit-FNA!25671F53F3F5
FireEyeGeneric.mg.25671f53f3f54b1e
EmsisoftGen:Heur.PonyStealer.Jm1@dmK!Icei (B)
JiangminTrojan.GandCrypt.qy
WebrootW32.Trojan.Gen
AviraTR/AD.GandCrab.hmh
Antiy-AVLTrojan/Generic.ASMalwS.298A880
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/VBInject.AIE!bit
GDataGen:Heur.PonyStealer.Jm1@dmK!Icei
AhnLab-V3Win-Trojan/VBKrypt.RP05.X1878
McAfeeFareit-FNA!25671F53F3F5
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Androm
MalwarebytesTrojan.MalPack.VB.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMA.hp
YandexTrojan.GandCrypt!L605SGB4xNg
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GuLoader.VHIX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.GandCrypt.gpz?

Trojan-Ransom.Win32.GandCrypt.gpz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment