Ransom Trojan

About “Trojan.Ransom.FortuneCrypt.A” infection

Malware Removal

The Trojan.Ransom.FortuneCrypt.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.FortuneCrypt.A virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Ransom.FortuneCrypt.A?


File Info:

name: BFDBE21AED7E7544CC07.mlw
path: /opt/CAPEv2/storage/binaries/c26192e7b14991ed39d6586f8c88a86af4467d5e296f75487bb62b920dea533f
crc32: 00821143
md5: bfdbe21aed7e7544cc079bea807afec7
sha1: 5482fd9d08c35222e6b6388eacad08cac29e1ebc
sha256: c26192e7b14991ed39d6586f8c88a86af4467d5e296f75487bb62b920dea533f
sha512: 03d9b174a066e51e16b43a4a2e8ca5feae5a8286d2c8d3c713a64fb11de3c32f56c62bbdcac0f771fc4c2fb7fb5698bb4e74938192275afae5096fc5772c9b0b
ssdeep: 49152:W8XNlko1sXp39wU31KVcklJ8MXjNJ2VF9AwAH1AmMAqLTWN:rKl6oVF9AwAH1AmMAD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DE52971E64685EDC8973A738D4EEABBB074134550002F4FFE9AAF18BB7A6C18D1510E
sha3_384: 51c5b01cc13f349fb9bfaae239d20a2dc81d4a8daa7b77f2b014fac4a011c1f600e3cd7a4a29dadf153937592e03db71
ep_bytes: 83ec1cc7042402000000ff15f0377000
timestamp: 2017-01-21 10:21:37

Version Info:

0: [No Data]

Trojan.Ransom.FortuneCrypt.A also known as:

BkavW32.Common.DD3DE99B
LionicTrojan.Win32.Crypren.j!c
MicroWorld-eScanTrojan.Ransom.FortuneCrypt.A
FireEyeTrojan.Ransom.FortuneCrypt.A
SkyhighTrojan-Ransom.g
ALYacTrojan.Ransom.FortuneCrypt
Cylanceunsafe
ZillyaTrojan.Filecoder.Win32.4800
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00507eb71 )
AlibabaRansom:Win32/Crypren.18cbc62a
K7GWTrojan ( 00507eb71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.FortuneCookie.A
KasperskyTrojan-Ransom.Win32.Crypren.afjg
BitDefenderTrojan.Ransom.FortuneCrypt.A
NANO-AntivirusTrojan.Win32.Filecoder.emjwjc
AvastFileRepMalware [Trj]
TencentMalware.Win32.Gencirc.10beb9a6
EmsisoftTrojan.Ransom.FortuneCrypt.A (B)
F-SecureTrojan.TR/Crypren.dqyxy
DrWebTrojan.Encoder.37801
VIPRETrojan.Ransom.FortuneCrypt.A
TrendMicroRansom_YAFCOOKIE.A
SophosMal/Generic-S
IkarusTrojan.Win32.Filecoder
GDataWin32.Trojan-Ransom.Faryou.A
JiangminTrojan.Crypren.rx
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypren.dqyxy
Antiy-AVLTrojan[Ransom]/Win32.Genasom
XcitiumMalware@#3t07sgp7n3rb3
ArcabitTrojan.Ransom.FortuneCrypt.A
ZoneAlarmTrojan-Ransom.Win32.Crypren.afjg
MicrosoftRansom:Win32/FileCryptor
CynetMalicious (score: 99)
McAfeeTrojan-Ransom.g
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Filecoder
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallRansom_YAFCOOKIE.A
RisingRansom.FileCryptor!8.1A7 (CLOUD)
MaxSecureTrojan.Malware.223586013.susgen
FortinetW32/Filecoder_FortuneCookie.A!tr
AVGFileRepMalware [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Ransom.FortuneCrypt.A?

Trojan.Ransom.FortuneCrypt.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment