Trojan

Trojan:Win32/GandCrypt.KMG!MTB removal

Malware Removal

The Trojan:Win32/GandCrypt.KMG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/GandCrypt.KMG!MTB virus can do?

  • Unconventionial language used in binary resources: Czech
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/GandCrypt.KMG!MTB?


File Info:

crc32: A564F724
md5: b8c4609370bf24b1ffba70eb626a2131
name: B8C4609370BF24B1FFBA70EB626A2131.mlw
sha1: 6999376f99047bd736d8341095381c697a6f7584
sha256: 4e32780b9824e48d04cd2f33cc17fad795654a3ac33b0c33fc65f60d2a7509a2
sha512: 73640f8460f730b42378f89d62bb5a27cf6d222d748a25cda7eb79a772d14bfe451ca94ee72ea2faf776b5c56f7c439dc0a9d90df2675ced20145c7fcced6314
ssdeep: 3072:giKhTNZyivqJWvMW1af6p1lx5chID/b5J7e9IdEvwtnAfN:gi4CiCJYfpt4vwt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sgfnghmj.exe
FileVersion: 8.4.3.12
Translation: 0x0809 0x04b0

Trojan:Win32/GandCrypt.KMG!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.166003
FireEyeGeneric.mg.b8c4609370bf24b1
CAT-QuickHealTrojan.Chapak.ZZ5
Qihoo-360Win32/Trojan.dc9
ALYacGen:Variant.Strictor.166003
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.373
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053483d1 )
BitDefenderGen:Variant.Strictor.166003
K7GWTrojan ( 0053483d1 )
Cybereasonmalicious.370bf2
CyrenW32/S-4543682a!Eldorado
SymantecRansom.GandCrab
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Ransomware.Generickdz-7131104-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.GandCrypt.febfvs
AegisLabTrojan.Win32.GandCrypt.tpvE
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
Ad-AwareGen:Variant.Strictor.166003
EmsisoftGen:Variant.Strictor.166003 (B)
ComodoTrojWare.Win32.Chapak.GH@7pk4uz
F-SecureHeuristic.HEUR/AGEN.1103328
DrWebTrojan.Encoder.24384
TrendMicroMal_HPGen-37b
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Mal/GandCrab-B
IkarusExploit.CVE-2015-1701
JiangminTrojan.GandCrypt.eq
AviraHEUR/AGEN.1103328
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Chapak
MicrosoftTrojan:Win32/GandCrypt.KMG!MTB
ArcabitTrojan.Strictor.D28873
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Strictor.166003
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab02.Exp
Acronissuspicious
McAfeeTrojan-FPTA!B8C4609370BF
VBA32TrojanRansom.GandCrypt
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GHTU
TrendMicro-HouseCallMal_HPGen-37b
TencentMalware.Win32.Gencirc.10b3a596
YandexTrojan.GenAsa!WpRX6D4GGig
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GKJF!tr
BitDefenderThetaGen:NN.ZexaF.34590.ny0@aapR0qkO
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureRansomeware.CRAB.gen

How to remove Trojan:Win32/GandCrypt.KMG!MTB?

Trojan:Win32/GandCrypt.KMG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment