Trojan

Should I remove “Trojan:Win32/GandCrypt.PC!MTB”?

Malware Removal

The Trojan:Win32/GandCrypt.PC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/GandCrypt.PC!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Detects Bitdefender Antivirus through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Enumerates services, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristics of BetaBot / Neurevt malware
  • Creates a hidden or system file
  • Attempts to identify installed analysis tools by a known file location
  • Attempts to identify installed AV products by registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a device
  • Detects VMware through the presence of a file
  • Detects VMware through the presence of a registry key
  • Attempts to modify browser security settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable browser security warnings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/GandCrypt.PC!MTB?


File Info:

crc32: E499C595
md5: ea4acb06f594dde31f5bd4862932f1de
name: upload_file
sha1: d62f15f53bf1d55357e3aecd83d93de1043192d8
sha256: a96869310ed26453df874d380555cc891068510413dd8702ef6ce850f8faef6a
sha512: b5f65b06bbe08e19ae295df84d2cfb61f9967b725e4ae7f5359d1a56bdda55c57abeee472882d79ae4c92e710a52632250b6a61b2d0541e623f0921969578569
ssdeep: 6144:FBOdZJ+zUArDFqjbGX07A5e9N3jJSkprdtOAppfAm9qOeTM:F4dv+oAtqjbGXv5MjJS+rdtJIm/2M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sracjoobz.exe
FileVers: 1.2.58
Copyright: Copyrighd (C) 2020, humke
TranslationUsi: 0x0032 0x0ccd

Trojan:Win32/GandCrypt.PC!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34837424
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.34837424
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056fc4c1 )
BitDefenderTrojan.GenericKD.34837424
K7GWTrojan ( 0056fc4c1 )
CrowdStrikewin/malicious_confidence_90% (W)
InvinceaMal/Generic-S
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HGWY
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Bsymem.gen
AlibabaTrojan:Win32/Kryptik.fcdd8c61
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.34837424
EmsisoftTrojan.GenericKD.34837424 (B)
DrWebTrojan.Siggen10.40021
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.ea4acb06f594dde3
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
GDataTrojan.GenericKD.34837424
WebrootW32.Trojan.Gen
MAXmalware (ai score=86)
ArcabitTrojan.Generic.D21393B0
ZoneAlarmHEUR:Trojan.Win32.Bsymem.gen
MicrosoftTrojan:Win32/GandCrypt.PC!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.R353521
Acronissuspicious
McAfeeRDN/Generic.grp
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.99 (RDMK:mBQ2QsD7hT37QLGrPx3Pdw)
IkarusTrojan-Banker.IcedID
FortinetPossibleThreat.PALLAS.H
AVGFileRepMalware
Cybereasonmalicious.53bf1d
Qihoo-360Generic/HEUR/QVM10.2.B77F.Malware.Gen

How to remove Trojan:Win32/GandCrypt.PC!MTB?

Trojan:Win32/GandCrypt.PC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment