Ransom Trojan

Trojan-Ransom.Win32.Crypmod.adxr removal tips

Malware Removal

The Trojan-Ransom.Win32.Crypmod.adxr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Crypmod.adxr virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Ransom.Win32.Crypmod.adxr?


File Info:

name: 269A6EF25D36E631F7BD.mlw
path: /opt/CAPEv2/storage/binaries/758df2d964e15451aa3a4d345c4aef445d41084900dc6cdc523391e12ab9339e
crc32: F3D0B60C
md5: 269a6ef25d36e631f7bded38d6398319
sha1: 750c683442c4acb75c3cdad19e01eb0b738ea044
sha256: 758df2d964e15451aa3a4d345c4aef445d41084900dc6cdc523391e12ab9339e
sha512: 701df1a7760a04b61be8ce5f3ece7f182191d49441df874ca17d04849949019304f22c4e1979419751f0aacee8d734fbe3b18d832d8f4aad6bf1b2d5472dd1da
ssdeep: 49152:CNC04srb/TLvO90dL3BmAFd4A64nsfJ7wWZi//MWuAFWkeCjgAHh3JK2nL1:CNMfwCpAFjnhJK
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T153C54B47F88184FEC5EBD2708965C6A2B6317845873123D32B60A7FA2FB6BD45E78350
sha3_384: 09ee28e680b2893753ba7c691097c3205ff75287c2a8cb6e343c37e34f5d4ff9b8e2b78d67d1b48a5c135b1d0bb8b712
ep_bytes: e95bc3ffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Crypmod.adxr also known as:

LionicTrojan.Win32.Crypmod.j!c
MicroWorld-eScanTrojan.GenericKD.38074277
FireEyeTrojan.GenericKD.38074277
McAfeeArtemis!269A6EF25D36
ZillyaTrojan.Crypmod.Win32.1475
AlibabaRansom:Win32/Crypmod.c3ac528d
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of WinGo/Agent.DG
APEXMalicious
KasperskyTrojan-Ransom.Win32.Crypmod.adxr
BitDefenderTrojan.GenericKD.38074277
AvastWin64:Malware-gen
Ad-AwareTrojan.GenericKD.38074277
TrendMicroRansom_Crypmod.R002C0WKM21
McAfee-GW-EditionBehavesLike.Win64.CoinMiner.vm
EmsisoftTrojan.GenericKD.38074277 (B)
IkarusTrojan.WinGo.Agent
GDataTrojan.GenericKD.38074277
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1141949
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.38074277
MAXmalware (ai score=82)
TrendMicro-HouseCallRansom_Crypmod.R002C0WKM21
FortinetPossibleThreat.PALLASNET.H
AVGWin64:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Ransom.Win32.Crypmod.adxr?

Trojan-Ransom.Win32.Crypmod.adxr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment