Ransom Trojan

Trojan-Ransom.Win32.Cryptor.fdv removal tips

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fdv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fdv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Trojan-Ransom.Win32.Cryptor.fdv?


File Info:

name: B32901F71C02779FACCA.mlw
path: /opt/CAPEv2/storage/binaries/66ac54169470cc974a51f8db549148e7b5c62639b38a68bb8b51eba67756e0fa
crc32: 9BCCCB7C
md5: b32901f71c02779facca9b5dc5546165
sha1: f842a62e3464e689ce4934879fc6e02214c5396c
sha256: 66ac54169470cc974a51f8db549148e7b5c62639b38a68bb8b51eba67756e0fa
sha512: c79a947dee95cfd446f991434724f2109ef94ef8696939575d18523750eeb0205ef1734842010e581806d8dfaaa5ef189b5912a1a04c2221c944af5a235f261e
ssdeep: 1536:b9EWW02ZOdWmnharz0w5J9oX6C1DUM3wMsorfI1:DLdWt0wvqXjxUuwMZrw1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BD4301D0CE6335A6CD5F663920DBD8C2676EFBA193256672258C2C4375F5202D0FEA07
sha3_384: 855d64933931e9695f25f0d1f14c2ab57c27623e6484034e3e0d56e6595c507d2ff955f1142538e8519b39163223c110
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fdv also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
McAfeeGenericRXQS-VX!B32901F71C02
CylanceUnsafe
SangforRansom.Win32.Cryptor.gen
K7AntiVirusTrojan ( 0058ac911 )
BitDefenderGen:Variant.Ransom.Sugar.17
K7GWTrojan ( 0058ac911 )
Cybereasonmalicious.71c027
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan-Ransom.Win32.Cryptor.fdv
RisingRansom.Cryptor!8.10A9 (CLOUD)
Ad-AwareGen:Variant.Ransom.Sugar.17
TACHYONRansom/W32.Enc.59392
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.b32901f71c02779f
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Ransom.Sugar.17
ZoneAlarmTrojan-Ransom.Win32.Cryptor.fdv
GDataGen:Variant.Ransom.Sugar.17
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
ALYacGen:Variant.Ransom.Sugar.17
MAXmalware (ai score=89)
VBA32BScope.TrojanRansom.Cryptor
MalwarebytesRansom.Encoded01
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B222
TencentWin32.Trojan.Filecoder.Pcij
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
BitDefenderThetaAI:Packer.456DD6081E
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Ransom.Win32.Cryptor.fdv?

Trojan-Ransom.Win32.Cryptor.fdv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment