Trojan

Trojan.MSCrypt.Python.Generic removal instruction

Malware Removal

The Trojan.MSCrypt.Python.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSCrypt.Python.Generic virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.MSCrypt.Python.Generic?


File Info:

name: 7C891A1F0BCD204BF516.mlw
path: /opt/CAPEv2/storage/binaries/915efbf8237eb4c059fcd11a6b0ec85ab40c9837e65c026941a11179ea278d5d
crc32: 363D45B1
md5: 7c891a1f0bcd204bf516d6d60227ae85
sha1: b1d6ff279ae3410907fb4445df0d8f82aaced171
sha256: 915efbf8237eb4c059fcd11a6b0ec85ab40c9837e65c026941a11179ea278d5d
sha512: 7b760cdc2352bbfa06a70d6ad3f5c5e190252d965b32bffececdad9aee0005d139f0e12ef315b12628b16053ea4a20a1fb324c55ac862c6d81068bf6621f9897
ssdeep: 196608:sRafMjFRCE0QXIenXCaG2ozXlT92FuppoiawJVOjmFj24M6P9B8PHsEWzqoI:GafWLX1SaGdTw0n0wyKBMIB8PHNWz
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1D6D633E94A910EF8E17A8B38D497A143D435FC2203E8CE4F27B557966F233A3583E644
sha3_384: aa7f0cc02c2d3cbc3dddd6d6956dc56efafc9bddb05d4a51a983c8986706bb1b66c10b253d34448f00340176a1b2dcc5
ep_bytes: 4883ec28e8670200004883c428e97afe
timestamp: 2023-05-12 09:00:43

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Windows Resource Leak Diagnostic
FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
InternalName: RdrLeakDiag.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: RdrLeakDiag.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.1
Translation: 0x0409 0x04b0

Trojan.MSCrypt.Python.Generic also known as:

DrWebTrojan.PWS.Stealer.35370
MicroWorld-eScanGen:Variant.Lazy.331494
McAfeeArtemis!7C891A1F0BCD
MalwarebytesTrojan.MSCrypt.Python.Generic
VIPREGen:Variant.Lazy.331494
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a56321 )
BitDefenderGen:Variant.Lazy.331494
K7GWTrojan ( 005a56321 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW64/ABRisk.ZFXB-0428
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/Packed.PyInstaller.E
KasperskyTrojan.Win32.Injuke.gzvw
AlibabaTrojan:Win32/Injuke.c1f18099
AvastWin64:Trojan-gen
RisingDropper.Injector!8.DC (CLOUD)
EmsisoftGen:Variant.Lazy.331494 (B)
F-SecureTrojan.TR/Redcap.wttvy
McAfee-GW-EditionBehavesLike.Win64.Generic.rc
FireEyeGen:Variant.Lazy.331494
SophosMal/Generic-S
GDataGen:Variant.Lazy.331494
GoogleDetected
AviraTR/Redcap.wttvy
MAXmalware (ai score=89)
ArcabitTrojan.Lazy.D50EE6
ZoneAlarmTrojan.Win32.Injuke.gzvw
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C5392786
ALYacGen:Variant.Lazy.331494
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H07EC23
TencentWin32.Trojan.Injuke.Bkjl
IkarusTrojan.Win64.Krypt
MaxSecureTrojan.Malware.121218.susgen
AVGWin64:Trojan-gen
DeepInstinctMALICIOUS

How to remove Trojan.MSCrypt.Python.Generic?

Trojan.MSCrypt.Python.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment