Malware

How to remove “Generic.Cryptor.X.9C5BA80A”?

Malware Removal

The Generic.Cryptor.X.9C5BA80A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Cryptor.X.9C5BA80A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Cryptor.X.9C5BA80A?


File Info:

crc32: 003DEB1D
md5: 6fd7f6a896112b50383e979a4209a088
name: 6FD7F6A896112B50383E979A4209A088.mlw
sha1: 2f68f67755d338156e8957949ac71380316bc221
sha256: 1cd93c07c439d16266f2276b1f38c53b57cd0de59490b6857044eda8abe78c01
sha512: e4072f413e1fcc32c89b6daeee3a29389b5bcbf12406e42d8c1d54b4abfa7340cc8cc757aed8c434dd3ff6989e0452eb5de234fe1fb927f70f8c5692bc387258
ssdeep: 6144:gCeJW1JQafCNkgbKSXaqWvhPpJdngTQ4zjGvWCpCCi8Y6r5AHknB9FL6:YWX9aNkgxWFpJNgTO3CoY6dAoC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Cryptor.X.9C5BA80A also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43330
CynetMalicious (score: 100)
ALYacTrojan.Agent.FormBook
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/FormBook.22d833d7
Cybereasonmalicious.755d33
CyrenW32/Kryptik.EUD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Formbook.AA
ZonerTrojan.Win32.116113
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderGeneric.Cryptor.X.9C5BA80A
MicroWorld-eScanGeneric.Cryptor.X.9C5BA80A
Ad-AwareGeneric.Cryptor.X.9C5BA80A
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34050.syZ@amWOIrdi
TrendMicroTROJ_FRS.VSNTH221
McAfee-GW-EditionRDN/Generic PWS.y
FireEyeGeneric.mg.6fd7f6a896112b50
EmsisoftGeneric.Cryptor.X.9C5BA80A (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/AD.Swotter.xrywv
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/FormBook.AL!MTB
ArcabitGeneric.Cryptor.X.9C5BA80A
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
GDataGeneric.Cryptor.X.9C5BA80A
AhnLab-V3Malware/Win.Cryptor.C4575974
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=80)
VBA32BScope.Backdoor.Androm
MalwarebytesTrojan.Injector
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.VSNTH221
RisingTrojan.Kryptik!1.D84E (CLASSIC)
IkarusTrojan.Inject
FortinetW32/Kryptik.HLWX!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cryptor.HwoCBWYC

How to remove Generic.Cryptor.X.9C5BA80A?

Generic.Cryptor.X.9C5BA80A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment