Ransom Trojan

How to remove “Trojan-Ransom.MSIL.Crusis”?

Malware Removal

The Trojan-Ransom.MSIL.Crusis is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.MSIL.Crusis virus can do?

  • Unconventionial language used in binary resources: Belarusian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan-Ransom.MSIL.Crusis?


File Info:

crc32: EA1B1A0E
md5: 9504b98b59611f8bb43354e8df4062f5
name: voc.exe
sha1: 3a019c2d8ca4b70e8e43e6fdf2388fb153a6299c
sha256: 297ff93e6a0c99ce848c4cfb739868d475b21be96d1d30c2eadc11312c9ff345
sha512: 44348c16695e00d737c2eabb49bd48a54c82515d2aa77f3f79cd2aad7ae33ec03c53ceb8b709e4f321b15f94da751acf485e2703ccc2f63330abb8382703c090
ssdeep: 12288:bVTu3RcehXsn8+mX/XhfSyxMTzVgP350vM:bVTu+us8+mpfxCGev
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.MSIL.Crusis also known as:

CylanceUnsafe
SangforMalware
Cybereasonmalicious.d8ca4b
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34098.Lm0@aSYPBHpG
CyrenW32/MSIL_Kryptik.WM.gen!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.SXL
APEXMalicious
KasperskyHEUR:Trojan-Ransom.MSIL.Crusis.gen
RisingBackdoor.Orcus!8.A4F3 (TFE:dGZlOg0p0aUtjdHjCA)
F-SecureHeuristic.HEUR/AGEN.1045749
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9504b98b59611f8b
SentinelOneDFI – Malicious PE
AviraHEUR/AGEN.1045749
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Crusis.gen
MalwarebytesTrojan.MSCrypt.MSIL.Generic
eGambitUnsafe.AI_Score_99%
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.C819.Malware.Gen

How to remove Trojan-Ransom.MSIL.Crusis?

Trojan-Ransom.MSIL.Crusis removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment