Ransom Trojan

Trojan-Ransom.Win32.Crypmodadv.xzo malicious file

Malware Removal

The Trojan-Ransom.Win32.Crypmodadv.xzo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Crypmodadv.xzo virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Crypmodadv.xzo?


File Info:

crc32: D493252E
md5: d0ca5a11c7d18936b53983bd440b86b3
name: D0CA5A11C7D18936B53983BD440B86B3.mlw
sha1: ce362108b2582817a0f0036a5a7ce28c68c804e7
sha256: 59819cae1457e80108cd84d538604dc10ebdd7e950d31f39ad95e326a31bed76
sha512: 6ce05b1cafdeb65e73b5cc3fce7e202db2620e9c81caa156a250df60f2602201d18e8ce9188bf10ec0171729579f4ce59aacbd4dbcd01e878bc3048b29e3fad5
ssdeep: 1536:8BpWEMO0caCaibPy3Vl/jJihdaTlZTZRAs0ulrADLb0A:83WEZaiQrwhdap1ZRsuliLb0A
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: c m d
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b1

Trojan-Ransom.Win32.Crypmodadv.xzo also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f99a61 )
LionicTrojan.Win32.Crypmodadv.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
ZillyaTrojan.Crypmodadv.Win32.192
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Crypmodadv.076cf964
K7GWTrojan ( 004f99a61 )
Cybereasonmalicious.1c7d18
CyrenW32/S-b5a1ff1e!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crypmodadv.xzo
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentWin32.Trojan.Crypmodadv.Wqwo
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
ComodoMalware@#3px79nqzmufbh
BitDefenderThetaGen:NN.ZexaF.34104.fy1@aqKFNugQ
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionRansomware-GJA!D0CA5A11C7D1
FireEyeGeneric.mg.d0ca5a11c7d18936
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Crypmodadv.hv
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.29DFC5E
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.Ransom.CryptXXX.1
SUPERAntiSpywareRansom.Cerber/Variant
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.R188553
Acronissuspicious
McAfeeRansomware-GJA!D0CA5A11C7D1
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Generic@ML.100 (RDML:sibfV/8CpxuLpjrzpWjpQw)
YandexTrojan.GenAsa!hlMKCw9OFj0
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Crypmodadv.xzo?

Trojan-Ransom.Win32.Crypmodadv.xzo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment