Ransom Trojan

Trojan-Ransom.Win32.GandCrypt.irj removal instruction

Malware Removal

The Trojan-Ransom.Win32.GandCrypt.irj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GandCrypt.irj virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.bit
a.tomx.xyz
emsisoft.bit
gandcrab.bit

How to determine Trojan-Ransom.Win32.GandCrypt.irj?


File Info:

crc32: 259BDEA1
md5: c541eade4c4f8d0501e44b1e468fd0b6
name: C541EADE4C4F8D0501E44B1E468FD0B6.mlw
sha1: 6755a98126173f626575d5915225fa6952f65885
sha256: afcd6f598d32bf4b3a44af039ed11575473eb8fba030eb4139a970a81adff2e6
sha512: d294de9cef4e26c4241c5ae7303f0284cf0f7b678a7c48f5e27c0c666075bf3cfbc138977aa73c7603076657b8e101d8f58f2a07d7137e24523d707b0323bc9c
ssdeep: 3072:lHtrUcB/la6TUPjX0o5soFydvaqUtZ5S:lH+hywjX0m4ha5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.GandCrypt.irj also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.BRMon.Gen.3
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeePacked-ZG!C541EADE4C4F
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.92
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/GandCrypt.13c5419c
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.e4c4f8
BitDefenderThetaGen:NN.ZexaF.34758.iuW@aOdmPxo
CyrenW32/S-c5d37cab!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GCRV
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.GandCrypt.irj
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.Miner.expeum
SUPERAntiSpywareTrojan.Agent/Gen-Bunitu
TencentMalware.Win32.Gencirc.10c88bc2
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-R + Mal/Kryptik-BN
ComodoApplication.Win32.IStartSurf.PS@8c4m91
DrWebTrojan.Encoder.24384
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.NeutrinoPOS.cc
AviraHEUR/AGEN.1117310
ArcabitTrojan.BRMon.Gen.3
AegisLabTrojan.Win32.GandCrypt.j!c
ZoneAlarmTrojan-Ransom.Win32.GandCrypt.irj
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
VBA32TrojanBanker.NeutrinoPOS
MAXmalware (ai score=98)
MalwarebytesTrojan.Bunitu
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingTrojan.Generic@ML.96 (RDML:AXsGXAGWkCRrIv6yY3ipAQ)
YandexTrojan.GenAsa!HVqu6tw5lsU
IkarusTrojan.Crypt
FortinetW32/GenKryptik.BAZY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.GandCrypt.irj?

Trojan-Ransom.Win32.GandCrypt.irj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment