Ransom

About “Ransom:Win32/Cryptor!MSR” infection

Malware Removal

The Ransom:Win32/Cryptor!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Cryptor!MSR virus can do?

  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Cryptor!MSR?


File Info:

crc32: 59F8F7B3
md5: 3d0c22b49f8608be142120162461eb1e
name: 3D0C22B49F8608BE142120162461EB1E.mlw
sha1: 2cd5e0a0c2b8659abecb89b7bf40fd6be74f8d58
sha256: b0d90577f361a9b60073a6433d5965759992498a5c8f62b7932def36853f6bef
sha512: fbcf0357376e205fb856ca08bf8ad34c8c26f49b2c5d141e1781646bb9142942a954379634c3e6632d14aad4ef8b80550de2b557b6cfcd580032646b94a1ff39
ssdeep: 3072:fRbikPFbtOKRhjzl5h38JtLCMqqDLc5XFt:fROk7PV8Jt9qqDGXP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Cryptor!MSR also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop11.51552
CynetMalicious (score: 99)
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1305132
SangforRansom.Win32.Cryptor.MSR
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000027
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.49f860
SymantecDownloader
ESET-NOD32Win32/Filecoder.OBF
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Doina.11234
NANO-AntivirusTrojan.Win32.Filecoder.hgjumu
MicroWorld-eScanGen:Variant.Doina.11234
Ad-AwareGen:Variant.Doina.11234
BitDefenderThetaGen:NN.ZexaF.34770.guX@aKlKbUni
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Cryptor.R002C0DCV21
McAfee-GW-EditionRansomware-GXK!3D0C22B49F86
FireEyeGeneric.mg.3d0c22b49f8608be
EmsisoftGen:Variant.Doina.11234 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.cqcv
AviraTR/Ransom.hrjej
Antiy-AVLTrojan/Generic.ASMalwS.3021DEA
MicrosoftRansom:Win32/Cryptor!MSR
ArcabitTrojan.Doina.D2BE2
AegisLabTrojan.Win32.Agent.trqD
GDataGen:Variant.Doina.11234
AhnLab-V3Malware/Win32.Generic.C4017808
McAfeeRansomware-GXK!3D0C22B49F86
MAXmalware (ai score=100)
VBA32TrojanRansom.Cryptor
MalwarebytesTrojan.Crypt.PADDED.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.VHDLOCKER.SM
RisingRansom.VHDLocker!1.C88A (CLASSIC)
YandexTrojan.GenAsa!/nRUj8PgEhE
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.116209723.susgen
FortinetW32/VHD.OBF!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwoCRB8A

How to remove Ransom:Win32/Cryptor!MSR?

Ransom:Win32/Cryptor!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment