Ransom Trojan

What is “Trojan-Ransom.Win32.Crypren.adwd”?

Malware Removal

The Trojan-Ransom.Win32.Crypren.adwd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Crypren.adwd virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Trojan-Ransom.Win32.Crypren.adwd?


File Info:

crc32: E2D6CB2A
md5: 789ddca4997c12659f23936c4f91e0e5
name: 789DDCA4997C12659F23936C4F91E0E5.mlw
sha1: 4eff0164995dc108e964357b0ac67e3da4a4bfe7
sha256: c0fd4fa1888a8bc1507b89e6121607ed8ec444bbb7d345519666fc09e577daff
sha512: 26872d92cc80ad1e9c3b80ea51cd7a3db055b1618dafe842424744b70ced1ea42808ca161cfa4366e68011c863f22337a2b059e057d83a759130766c1bd187a1
ssdeep: 6144:p67YIXdfrCwK15bGWiak+/zahZaeuRKF:oYwo5KfCSZa
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: RBY
Assembly Version: 1.0.0.0
InternalName: Kryptonite.exe
FileVersion: 1.0.0.0
CompanyName: RBY
LegalTrademarks:
Comments: Fuck Superman
ProductName: Kryptonite
ProductVersion: 1.0.0.0
FileDescription: Kryptonite
OriginalFilename: Kryptonite.exe

Trojan-Ransom.Win32.Crypren.adwd also known as:

K7AntiVirusTrojan ( 004de29f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.14694
CynetMalicious (score: 100)
ALYacTrojan.Ransom.RBY
CylanceUnsafe
ZillyaTrojan.Crypren.Win32.528
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Crypren.f57e8ff3
K7GWTrojan ( 004de29f1 )
Cybereasonmalicious.4997c1
SymantecRansom.HiddenTear!g1
ESET-NOD32a variant of MSIL/Filecoder.AK
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crypren.adwd
BitDefenderTrojan.Ransomware.GenericKD.32574819
NANO-AntivirusTrojan.Win32.Crypren.esrekz
ViRobotTrojan.Win32.Z.Filecoder.211456
MicroWorld-eScanTrojan.Ransomware.GenericKD.32574819
TencentMalware.Win32.Gencirc.114d81c5
Ad-AwareTrojan.Ransomware.GenericKD.32574819
SophosMal/Generic-R + Troj/Ramsil-B
ComodoMalware@#2ax39kla3kuz6
BitDefenderThetaGen:NN.ZemsilF.34058.mq0@aCHI@3e
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_KRYPTONITE.B
McAfee-GW-EditionRansom-Krptnite!789DDCA4997C
FireEyeGeneric.mg.789ddca4997c1265
EmsisoftTrojan.Ransomware.GenericKD.32574819 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.binii
AviraHEUR/AGEN.1105326
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.21BE9DC
MicrosoftRansom:Win32/Genasom
ArcabitTrojan.Ransomware.Generic.D1F10D63
ZoneAlarmTrojan-Ransom.Win32.Crypren.adwd
GDataTrojan.Ransomware.GenericKD.32574819
TACHYONRansom/W32.DN-Crypren.211456
AhnLab-V3Trojan/Win32.Ransom.C2154363
McAfeeRansom-Krptnite!789DDCA4997C
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Crypren
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_KRYPTONITE.B
YandexTrojan.Filecoder!wTrumeVQ3A0
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.AK!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwMAOqkA

How to remove Trojan-Ransom.Win32.Crypren.adwd?

Trojan-Ransom.Win32.Crypren.adwd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment