Ransom Trojan

Trojan-Ransom.Win32.Crypmod.yja (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Crypmod.yja is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Crypmod.yja virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed

How to determine Trojan-Ransom.Win32.Crypmod.yja?


File Info:

crc32: 17F2156A
md5: 4500dc14614e072e253cb6c3285597c7
name: 4500DC14614E072E253CB6C3285597C7.mlw
sha1: d171769e2a3a3b3fa51af4c4a61e5a3fdc4bdfa1
sha256: 2806bb6cca242c226c5ffb253e2014bb7d66bc82cfaf73190fa23d78b41dd3cb
sha512: fac9173aa7f0940f83191e087af95e7ecaf5ef7baf15ca56bb177329ddbcfc63887927588fd2fe322dbbb5bd67bb2fd3b48c97f7a3e063bbea1d0f311e959fd0
ssdeep: 24576:TJlh9bDfArWR0lggFcqXAwyErVetsQbWTMkw9aBuDL1Dc6xir9yUvbE+PcsqTEd:TJoWR/wcBMqsQ6T2QMIxVPcsqTq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Crypmod.yja also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Encoder.10587
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.4640428
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Crypmod.72e3d4cf
Cybereasonmalicious.4614e0
SymantecTrojan.Gen
ESET-NOD32multiple detections
APEXMalicious
TotalDefenseWin32/FakeDoc_i
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crypmod.yja
BitDefenderTrojan.GenericKD.4640428
NANO-AntivirusTrojan.Win32.Crypmod.enfgxl
MicroWorld-eScanTrojan.GenericKD.4640428
TencentWin32.Trojan.Fakedoc.Auto
Ad-AwareTrojan.GenericKD.4640428
SophosMal/Generic-S
ComodoMalware@#3q8cgxzlh3rnz
BitDefenderThetaGen:NN.ZexaF.34608.pzZ@a8g6CxpO
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_VENUSLOCK.G
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.tc
FireEyeGeneric.mg.4500dc14614e072e
EmsisoftTrojan.GenericKD.4640428 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Nanocore.AC!MTB
ArcabitTrojan.Generic.D46CEAC
AegisLabTrojan.Win32.Malicious.4!e
GDataTrojan.GenericKD.4640428
McAfeeArtemis!4500DC14614E
MAXmalware (ai score=100)
VBA32Hoax.Crypmod
PandaTrj/CI.A
RisingRansom.FileCryptor!8.1A7 (CLOUD)
IkarusTrojan-Ransom.HiddenTears
FortinetGenerik.IGNTETS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.a24

How to remove Trojan-Ransom.Win32.Crypmod.yja?

Trojan-Ransom.Win32.Crypmod.yja removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment