Ransom

About “Ransom:Win32/FileCryptor” infection

Malware Removal

The Ransom:Win32/FileCryptor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/FileCryptor virus can do?

    How to determine Ransom:Win32/FileCryptor?

    
    

    File Info:

    crc32: 5410406B
    md5: 9c7c7149387a1c79679a87dd1ba755bc
    name: tmp6wb7jkwf
    sha1: 828001f20df60b6af286593c37644d39e5a6122a
    sha256: 3e6de9e2baacf930949647c399818e7a2caea2626df6a468407854aaa515eed9
    sha512: aa13bbd5b55be305f0dcd9bd5f6c43410219e3d889bd86d66f5644f2e12f4656c103179fa18a021e29a1f7294c7d7908164ef2fe8e26ff327acb6fd79fc1c4f8
    ssdeep: 3072:HrtSNbR+u/AewFrE1lG4t29xWa82swnlOi81Vyn0lIIk:LodZ/rl1lG4odnlOi8Pyn0l+
    type: PE32 executable (GUI) Intel 80386, for MS Windows

    Version Info:

    LegalCopyright: Copyright (C) 2016
    InternalName: Message
    FileVersion: 1, 0, 0, 1
    CompanyName:
    LegalTrademarks:
    ProductName: Message Application
    ProductVersion: 1, 0, 0, 1
    FileDescription: Message MFC Application
    OriginalFilename: Message.EXE
    Translation: 0x0409 0x04b0

    Ransom:Win32/FileCryptor also known as:

    BkavW32.WannaCryDBJ.Trojan
    MicroWorld-eScanTrojan.Ransom.BMC
    CAT-QuickHealRansom.FileCryptor.A4
    ALYacTrojan.Ransom.WannaCryptor
    CylanceUnsafe
    VIPRETrojan.Win32.Generic!BT
    SUPERAntiSpywareRansom.WannaCrypt/Variant
    SangforMalware
    K7AntiVirusRiskware ( 0040eff71 )
    AlibabaRansom:Win32/Wanna.7635dde3
    K7GWRiskware ( 0040eff71 )
    Cybereasonmalicious.9387a1
    BaiduWin32.Trojan.Ransom.c
    F-ProtW32/WannaCrypt.K
    SymantecRansom.Wannacry
    ESET-NOD32Win32/Filecoder.WannaCryptor.B
    APEXMalicious
    AvastWin32:Malware-gen
    ClamAVWin.Trojan.Agent-6319549-0
    GDataWin32.Trojan-Ransom.Filecoder.AQ
    KasperskyTrojan-Ransom.Win32.Wanna.al
    BitDefenderTrojan.Ransom.BMC
    NANO-AntivirusTrojan.Win32.Ransom.eowbkv
    Paloaltogeneric.ml
    ViRobotTrojan.Win32.WannaCryptor.184324
    RisingRansom.FileCryptor!8.1A7 (KTSE)
    Ad-AwareTrojan.Ransom.BMC
    SophosTroj/Wanna-K
    ComodoMalware@#ujbtk9wr4uue
    F-SecureTrojan.TR/FileCoder.gafeo
    DrWebTrojan.Encoder.10656
    ZillyaTrojan.Filecoder.Win32.5026
    TrendMicroRansom_WCRY.SM
    McAfee-GW-EditionRansom-O.g
    FireEyeGeneric.mg.9c7c7149387a1c79
    EmsisoftTrojan.FileCoder (A)
    SentinelOneDFI – Suspicious PE
    CyrenW32/Trojan.HMOH-6307
    JiangminTrojan.WanaCry.l
    WebrootW32.Trojan.Ransom
    AviraTR/FileCoder.gafeo
    eGambitTrojan.Generic
    Antiy-AVLTrojan/Win32.TSGeneric
    Endgamemalicious (high confidence)
    ArcabitTrojan.Ransom.BMC
    AegisLabTrojan.Win32.Wanna.toNN
    ZoneAlarmTrojan-Ransom.Win32.Wanna.al
    MicrosoftRansom:Win32/FileCryptor
    TACHYONRansom/W32.WannaCry.184320
    AhnLab-V3Trojan/Win32.Wannacryptor.R200578
    McAfeeRansom-O.g
    MAXmalware (ai score=100)
    VBA32BScope.TrojanRansom.Wanna
    ZonerTrojan.Win32.59000
    TrendMicro-HouseCallRansom_WCRY.SM
    TencentTrojan.Win32.WannaCry.l
    YandexTrojan.Wanna!
    IkarusTrojan-Ransom.WannaCry
    MaxSecureTrojan.Malware.1728101.susgen
    FortinetW32/Generic.AC.3EE619!tr
    BitDefenderThetaGen:NN.ZexaF.34126.lq0@aCVIagki
    AVGWin32:Malware-gen
    PandaTrj/WLT.C
    CrowdStrikewin/malicious_confidence_100% (W)
    Qihoo-360Trojan.Generic

    How to remove Ransom:Win32/FileCryptor?

    Ransom:Win32/FileCryptor removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment