Categories: Ransom

About “Ransom.FileCryptor” infection

The Ransom.FileCryptor file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Ransom.FileCryptor virus can do?

  • Freezing computer.
  • New home page in browsers.
  • Ads and pop-ups on desktop and browser.
  • Very slow loading speed of webpages.
  • Computer work slower then usual.

How to determine Ransom.FileCryptor?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: W32/Trojan.SIOP-2317

File Info:

Name: 5.exe

Size: 474624

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: b1cfe57dd34b0ab8379733cf3f368be4

SHA1: 706f7e56d6843a84315c574c2182eb94734f47d3

SH256: 36213f57ceabe23ef76ec56f006c6fc1a1f03a6c94949b0f14b8e6dec26af98b

Version Info:

[No Data]

Ransom.FileCryptor also known as:

ALYac Trojan.Ransom.Stop
APEX Malicious
AVG Win32:TrojanX-gen [Trj]
Acronis suspicious
Ad-Aware Trojan.GenericKD.32699187
AhnLab-V3 Trojan/Win32.MalPe.R298432
Alibaba Trojan:Win32/Chapak.3b0d223b
Antiy-AVL Trojan/Win32.Chapak
Arcabit Trojan.Generic.D1F2F333
Avast Win32:TrojanX-gen [Trj]
Avira TR/Crypt.XPACK.gpqez
BitDefender Trojan.GenericKD.32699187
BitDefenderTheta Gen:NN.ZexaF.32251.Cu0@a8Ev6eg
CAT-QuickHeal Trojan.Multi
Comodo Malware@#2r8uymrge3g8b
CrowdStrike win/malicious_confidence_90% (W)
Cybereason malicious.6d6843
Cylance Unsafe
Cyren W32/Trojan.SIOP-2317
DrWeb Trojan.Packed2.42094
ESET-NOD32 a variant of Win32/Kryptik.GYDV
Endgame malicious (high confidence)
F-Secure Trojan.TR/Crypt.XPACK.gpqez
FireEye Generic.mg.b1cfe57dd34b0ab8
Fortinet W32/Kryptik.GYEF!tr
GData Trojan.GenericKD.32699187
Ikarus Trojan.Win32.Krypt
Invincea heuristic
Jiangmin Trojan.Chapak.hsn
K7AntiVirus Trojan ( 0055b2af1 )
K7GW Trojan ( 0055b2af1 )
Kaspersky Trojan.Win32.Chapak.ecgp
MAX malware (ai score=100)
Malwarebytes Ransom.FileCryptor
MaxSecure Trojan.Malware.74684616.susgen
McAfee RDN/Generic.grp
McAfee-GW-Edition BehavesLike.Win32.MultiPlug.gc
MicroWorld-eScan Trojan.GenericKD.32699187
Microsoft Trojan:Win32/CryptInject.CB!MTB
NANO-Antivirus Trojan.Win32.Chapak.ghmdjt
Paloalto generic.ml
Panda Generic Malware
Qihoo-360 Win32/Trojan.fc8
Rising Trojan.Wacatac!8.10C01 (TFE:5:QctkJtJDusT)
SentinelOne DFI – Suspicious PE
Sophos Mal/GandCrab-G
Symantec Packed.Generic.525
TrendMicro TROJ_GEN.R002C0RKA19
TrendMicro-HouseCall Trojan.Win32.SMOKELOAD.SMC2.hp
VBA32 BScope.Trojan.Dynamer
VIPRE Trojan.Win32.Generic!BT
ViRobot Trojan.Win32.S.Infostealer.474624
Webroot W32.Trojan.Gen
Yandex Trojan.Chapak!
Zillya Trojan.Chapak.Win32.84806
ZoneAlarm Trojan.Win32.Chapak.ecgp

How to remove Ransom.FileCryptor?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Trojan:Win32/Antavmu!pz (file analysis)

The Trojan:Win32/Antavmu!pz is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago

Trojan.Win32.Agent.xblxqs removal instruction

The Trojan.Win32.Agent.xblxqs is considered dangerous by lots of security experts. When this infection is active,…

10 mins ago

TrojanDownloader:Win32/Wintrim.BH malicious file

The TrojanDownloader:Win32/Wintrim.BH is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

About “Trojan:Win32/C2Lop.E” infection

The Trojan:Win32/C2Lop.E is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

Trojan.Dropper.AAAM malicious file

The Trojan.Dropper.AAAM is considered dangerous by lots of security experts. When this infection is active,…

40 mins ago

Win64/Kryptik.EHF removal instruction

The Win64/Kryptik.EHF is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago