Ransom Trojan

About “Trojan-Ransom.Win32.Crusis.dzn” infection

Malware Removal

The Trojan-Ransom.Win32.Crusis.dzn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Crusis.dzn virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Trojan-Ransom.Win32.Crusis.dzn?


File Info:

crc32: 45342F23
md5: a4ff228261bda2f29cf839970cde0eb8
name: A4FF228261BDA2F29CF839970CDE0EB8.mlw
sha1: b416d467cc2dda1d3d32cc38a91f9649bd96f822
sha256: 4676b8bceb480f1f09c383854a292302da241c3999f4371a93001e4e5877aa8d
sha512: 9c9ac00021bfa90fd79df79ddd4f057b939b27c4bdd494116e6602bd4724bc72c0650221cd066b95187118155cc76bd967a65c1bdc0509945e45356cd31a5cbe
ssdeep: 6144:ElASxA2hk5DIwjQwSeJoEKZAMG/A8nEo1mxg1ChWlqPm3JBw5SUaRgRU3:Elm2hkPj9oEHMG/A8Eqcg1COEWRD
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9. All rights reserved.
CompanyName: AppDirect
Comments: Outlines Simulates Mrever Del One From
ProductName: Statement
ProductVersion: 8.3.7.5
FileDescription: Outlines Simulates Mrever Del One From
OriginalFilename: Statement.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Crusis.dzn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055d3741 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Crysis
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.11373
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Crusis.77f89ad5
K7GWTrojan ( 0055d3741 )
Cybereasonmalicious.261bda
CyrenW32/Crysis.IYQH-5536
SymantecTrojan Horse
ESET-NOD32Win32/Filecoder.Crysis.P
ZonerTrojan.Win32.87016
APEXMalicious
AvastOther:Malware-gen [Trj]
KasperskyTrojan-Ransom.Win32.Crusis.dzn
BitDefenderTrojan.GenericKD.32803158
NANO-AntivirusTrojan.Win32.Filecoder.gureaq
MicroWorld-eScanTrojan.GenericKD.32803158
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKD.32803158
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#20nk8ajrnkfz4
BitDefenderThetaGen:NN.ZexaF.34688.xmKfaW5nNDpi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.DHARMA.NN
McAfee-GW-EditionBehavesLike.Win32.ICLoader.fc
FireEyeGeneric.mg.a4ff228261bda2f2
EmsisoftTrojan.GenericKD.32803158 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Crusis.aij
WebrootW32.Ransom.Crysis
AviraTR/Crypt.XPACK.tkrtm
Antiy-AVLTrojan/Generic.ASMalwS.2D5CF73
MicrosoftTrojan:Win32/Skeeyah.A!MTB
GDataWin32.Trojan-Ransom.VirusEncoder.99N24S
AhnLab-V3Trojan/Win32.FileCoder.C3634747
McAfeeRansomware-GUK!A4FF228261BD
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Crusis
PandaTrj/WLT.F
TrendMicro-HouseCallRansom.Win32.DHARMA.NN
RisingRansom.Crysis!8.32B9 (KTSE)
YandexTrojan.Crusis!Kg5MFblL9fk
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.74733723.susgen
FortinetW32/Filecoder_Crysis.P!tr.ransom
AVGOther:Malware-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Crusis.dzn?

Trojan-Ransom.Win32.Crusis.dzn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment