Trojan

How to remove “Trojan:Win32/GandCrypt.PVB!MTB”?

Malware Removal

The Trojan:Win32/GandCrypt.PVB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/GandCrypt.PVB!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

rb3.ftnt.io

How to determine Trojan:Win32/GandCrypt.PVB!MTB?


File Info:

crc32: D28E2271
md5: e53a0b86a6b4e2e160a0a0185aa29c01
name: fsa_downloader_a56d7c.exe
sha1: abf6f672bb69cfcce6f044c2888954795638677e
sha256: 072212f9e51125f09ab1b2d76531a9405cba7952cffc2abf2937a4a741a56d7c
sha512: 5dc658a74f12ba3e784e16c1cc3642b8c0aa7a2007f176111f9cd7a28eb3bd9056248f06f9976f57f6851d142e2e8e3592732bfbbb3e6f380d83c1155321e89d
ssdeep: 48:odTxwOZv1wOZGZdPkwOW1wAPFsXEJfmbJTtor5BPr:oJxwOZv1wOZGZdPkwOW1wAPF+OfmdI5
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/GandCrypt.PVB!MTB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.TestSample.B
FireEyeGeneric.mg.e53a0b86a6b4e2e1
CAT-QuickHealTrojan.Wacatac
McAfeeGenericRXHA-OK!E53A0B86A6B4
CylanceUnsafe
AegisLabTrojan.Win32.TestSample.4!c
SangforMalware
K7AntiVirusTrojan ( 005692221 )
BitDefenderTrojan.TestSample.B
K7GWTrojan ( 005692221 )
Cybereasonmalicious.6a6b4e
TrendMicroTROJ_GEN.R015C0PFA20
CyrenW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
AlibabaTrojan:Application/Generic.af9bf2a0
Endgamemalicious (high confidence)
SophosTroj/AutoG-ER
ComodoTrojWare.Win32.Agent.SFSC@8t0i0z
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPRETrojan-Downloader.Win32.Small!cobra (v)
Invinceaheuristic
EmsisoftTrojan.TestSample.B (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Downloader-Sml!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/GandCrypt.PVB!MTB
ArcabitTrojan.TestSample.B
GDataTrojan.TestSample.B
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34130.amW@a4Uqt!o
ALYacTrojan.TestSample.B
MAXmalware (ai score=87)
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesRiskWare.TestSample
TrendMicro-HouseCallTROJ_GEN.R015C0PFA20
RisingTrojan.Occamy!8.F1CD (RDMK:cmRtazpsVFcWAEsMsFdCJ/S5jP/z)
IkarusTrojan.TestSample
Ad-AwareTrojan.TestSample.B
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM20.1.D5FB.Malware.Gen

How to remove Trojan:Win32/GandCrypt.PVB!MTB?

Trojan:Win32/GandCrypt.PVB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment