Ransom Trojan

How to remove “TrojanRansom.GandCrypt”?

Malware Removal

The TrojanRansom.GandCrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanRansom.GandCrypt virus can do?

  • Unconventionial language used in binary resources: Spanish (Guatemala)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine TrojanRansom.GandCrypt?


File Info:

crc32: 6855003E
md5: b934c9da365be37c2061f90353aca169
name: B934C9DA365BE37C2061F90353ACA169.mlw
sha1: 38220f041a8cb13dcf046f2259018d848ec75167
sha256: 7b1f06ea5c1987478e166b727a60cf6e2876248a984cb5541676b93706473c23
sha512: bfc3727caa1b1cd4399531a16d793a33981ad20dc66e87792732cd621f5b45f503ead3d17ff95c9b6aec09ddb8c3224461de26ef7a0a04b1d4d928833ad1d0fa
ssdeep: 3072:CvXjcSvDvSVxu9SM2PCzwQ3sOtBNPsolKzxTBodtV+oywGGw46dgTnmot54RS+W:kjcAujMPF0otggGcN7+UsAuqzA+XZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanRansom.GandCrypt also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.64194
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
ZillyaTrojan.Generic.Win32.400157
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00527a681 )
Cybereasonmalicious.a365be
CyrenW32/S-c07995ba!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GDKV
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.Kryptik.eyexzh
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentMalware.Win32.Gencirc.10b84d25
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-R + Mal/Agent-AUL
ComodoTrojWare.Win32.Cloxer.AY@7o68fu
BitDefenderThetaGen:NN.ZexaF.34608.qyW@aahehqH
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.b934c9da365be37c
EmsisoftTrojan.BRMon.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1103299
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.BRMon.Gen.3
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BRMon.Gen.3
AhnLab-V3Trojan/Win32.Magniber.R220698
Acronissuspicious
McAfeeGenericRXEC-RH!B934C9DA365B
MAXmalware (ai score=100)
VBA32TrojanRansom.GandCrypt
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingTrojan.Kryptik!1.B048 (CLASSIC)
YandexTrojan.GenAsa!co0M/8UU9fE
IkarusTrojan.Win32.Predator
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.CNAR!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.1f2

How to remove TrojanRansom.GandCrypt?

TrojanRansom.GandCrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment