Malware

Sf:Crypt-AR [Trj] malicious file

Malware Removal

The Sf:Crypt-AR [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Sf:Crypt-AR [Trj] virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

How to determine Sf:Crypt-AR [Trj]?


File Info:

crc32: 26D007FD
md5: 37646dbdca7e2f26b907890716ae677e
name: 37646DBDCA7E2F26B907890716AE677E.mlw
sha1: 0212388098fb3ba9442f3bcd19d0cdd9f4354553
sha256: 41f7661aef70677f62f2a31ffea53eef975870ff663b7c3f2006168d5cbdb8ee
sha512: f38823d150d1e65d3e1fa69b476a303bc55e5d44c78f1ae97c80a0a4ec68a23106caa082231ae897b37db31c5665702881e7d0a2d8118afaaa8c7859af76a8fb
ssdeep: 6144:nLbii5bkgVuN+xSKV7Wkrsf7LsKr1wcFXGd4WfX:nXikbkgaISKVqRlFGX
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
InternalName: 7z.sfx
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription: 7z Console SFX
OriginalFilename: 7z.sfx.exe
Translation: 0x0409 0x04b0

Sf:Crypt-AR [Trj] also known as:

K7AntiVirusTrojan ( 0040fa3d1 )
DrWebTrojan.Encoder.514
CAT-QuickHealRansom.Crowti.A4
ALYacTrojan.GenericKD.30827748
CylanceUnsafe
SangforRansom.Win32.Crowti.A
AlibabaRansom:Win32/Cryptodef.c9a6b75f
K7GWTrojan ( 0040fa3d1 )
Cybereasonmalicious.dca7e2
CyrenW32/S-5799ca41!Eldorado
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Filecoder.CryptoWall.D
AvastSf:Crypt-AR [Trj]
ClamAVWin.Ransomware.Upatre-7101380-0
KasperskyTrojan-Ransom.Win32.Cryptodef.cjb
BitDefenderTrojan.GenericKD.30827748
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.30827748
TencentWin32.Trojan.Cryptodef.Ljua
Ad-AwareTrojan.GenericKD.30827748
SophosMal/Generic-R + Troj/Ransom-AGU
ComodoMalware@#p1ze6p5kt3ko
BitDefenderThetaAI:Packer.C62FF6921E
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_CRYPWALL.SNN
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeTrojan.GenericKD.30827748
EmsisoftTrojan.GenericKD.30827748 (B)
JiangminTrojan/Blocker.kur
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.E56A05
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Crowti.A
GDataTrojan.GenericKD.30827748
McAfeeGeneric.dtd
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Spy
MalwarebytesTrojan.CryptoLocker
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_CRYPWALL.SNN
RisingTrojan.Generic@ML.100 (RDML:tS3TGfrfRdbav5Xdl4nQ1g)
YandexTrojan.Cryptodef!yrV9l90cYkY
IkarusTrojan.Win32.Filecoder
FortinetW32/RANSOM.AGU!tr
AVGSf:Crypt-AR [Trj]
Qihoo-360Win32/Ransom.Cryptodef.HgAASREA

How to remove Sf:Crypt-AR [Trj]?

Sf:Crypt-AR [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment