Malware

About “Generic.Cryptor.X.43ED78CF” infection

Malware Removal

The Generic.Cryptor.X.43ED78CF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Cryptor.X.43ED78CF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Cryptor.X.43ED78CF?


File Info:

crc32: F3D0BE96
md5: 6e2ed633f26fe572da0d924ff1dc7648
name: 6E2ED633F26FE572DA0D924FF1DC7648.mlw
sha1: 0ebb42c762f291398cc6d5d8efb085fdc831dac4
sha256: 51867b6cbe6c0ea32eff283bc03852dcf190514adfb84128af619ab815227a70
sha512: d7dbc8973536adee4f8a67acd7ed82ccf823827361889ce1e291dabb78d3ec5509fa10492bf0ed0dc5e88a58a790ab05e54bf1fe8f129a1a98b80a876a8d06ce
ssdeep: 12288:tBn0RN617gNm5YnXDdRgMVahjLySXJGJjquVb/+CXOnfasfF:tBn0RNlDdRg6axmSgxRZ+CXOnNfF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Cryptor.X.43ED78CF also known as:

K7AntiVirusTrojan ( 005807271 )
LionicTrojan.Win32.Agensla.i!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.53796
CynetMalicious (score: 100)
CAT-QuickHealTrojanpws.Agensla
ALYacGeneric.Cryptor.X.43ED78CF
CylanceUnsafe
ZillyaTrojan.Agensla.Win32.14732
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/FormBook.e5dee3df
K7GWTrojan ( 005807271 )
CyrenW32/Kryptik.EVG.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HLYK
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Smdd-6956905-0
KasperskyHEUR:Trojan-PSW.Win32.Agensla.gen
BitDefenderGeneric.Cryptor.X.43ED78CF
ViRobotTrojan.Win32.Z.Win.550515
MicroWorld-eScanGeneric.Cryptor.X.43ED78CF
TencentMalware.Win32.Gencirc.10cea596
Ad-AwareGeneric.Cryptor.X.43ED78CF
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.rpxcp@0
BitDefenderThetaGen:NN.ZexaE.34126.HyZ@ayrBEAni
TrendMicroTrojanSpy.Win32.LOKI.PUHBAZCLQW
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.6e2ed633f26fe572
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Agensla.qa
AviraTR/Crypt.Agent.ncrmx
Antiy-AVLTrojan/Generic.ASMalwS.345E402
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/FormBook.SM!MTB
GDataWin32.Trojan.PSE.1V9N73W
AhnLab-V3Malware/Win.Cryptor.R435861
McAfeeGenericRXPN-XS!6E2ED633F26F
MAXmalware (ai score=87)
VBA32BScope.TrojanSpy.Noon
MalwarebytesSpyware.PasswordStealer.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.PUHBAZCLQW
RisingTrojan.Kryptik!1.D84E (CLASSIC)
YandexTrojan.Kryptik!NJJjxQJPPyc
IkarusTrojan.Agent
FortinetW32/GenKryptik.FILN!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.Cryptor.X.43ED78CF?

Generic.Cryptor.X.43ED78CF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment