Ransom Trojan

What is “Trojan-Ransom.MSIL.Crypmodadv”?

Malware Removal

The Trojan-Ransom.MSIL.Crypmodadv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.MSIL.Crypmodadv virus can do?

  • Creates RWX memory

Related domains:

www.legoiner.ga

How to determine Trojan-Ransom.MSIL.Crypmodadv?


File Info:

crc32: D8761D16
md5: 5e6c4ff85c6b88fd0581b071dfb6e2cc
name: 5E6C4FF85C6B88FD0581B071DFB6E2CC.mlw
sha1: f0f0d3009a0b741aaa6c5de92571528481752045
sha256: 4c96a6af8bb23b9e3940fac76acc729a6ab090c1c2409ce7292035e606e47d63
sha512: 0c1ede9b85b58ab0765d86e4434e8801a968eca2696ff01d7eaac5d4b6f33ae5059de5722d3b8c2390eae1ca4eb8ce856276fe5b660609081b7241571a9760e4
ssdeep: 1536:NzAMwflmsolaTIrRuw+mqbz9j1MWLQsfUTRfh:uM+lmsolAIrRuw+mqv9j1MWLQXTX
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 2.1.0.0
InternalName: xbot.exe
FileVersion: 2.1.0.0
ProductVersion: 2.1.0.0
FileDescription:
OriginalFilename: xbot.exe

Trojan-Ransom.MSIL.Crypmodadv also known as:

K7AntiVirusTrojan ( 004ddf631 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10598
CynetMalicious (score: 99)
ALYacGen:Variant.Ransom.HiddenTear.1
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7510
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004ddf631 )
Cybereasonmalicious.85c6b8
SymantecTrojan.Bleagle
ESET-NOD32a variant of MSIL/Filecoder.AK
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Crypmodadv.gen
BitDefenderGen:Variant.Ransom.HiddenTear.1
NANO-AntivirusTrojan.Win32.Filecoder.eibowq
MicroWorld-eScanGen:Variant.Ransom.HiddenTear.1
TencentWin32.Trojan.Generic.Syim
Ad-AwareGen:Variant.Ransom.HiddenTear.1
SophosML/PE-A + Troj/Cryptear-A
BitDefenderThetaGen:NN.ZemsilF.34690.hm0@ayuCsAj
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTEAR.SM0
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.5e6c4ff85c6b88fd
EmsisoftGen:Variant.Ransom.HiddenTear.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ambax
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1129952
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:MSIL/Ryzerlo.A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ransom.HiddenTear.1
AhnLab-V3Trojan/Win32.Agent.R325129
McAfeeArtemis!5E6C4FF85C6B
MAXmalware (ai score=100)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTEAR.SM0
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.Agent!5flb7nnmb+8
IkarusTrojan-Ransom.HiddenTear
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.AK!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.MSIL.Crypmodadv?

Trojan-Ransom.MSIL.Crypmodadv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment