Ransom Trojan

Trojan-Ransom.Win32.Cryptor.fea removal guide

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fea is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fea virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Trojan-Ransom.Win32.Cryptor.fea?


File Info:

name: 434253847FE9B9ECEF23.mlw
path: /opt/CAPEv2/storage/binaries/36a9c7e15713611fd30bb98777ef3e01c7d31059cbd925b9b7a8ddfca12fb13c
crc32: 4BFA67A1
md5: 434253847fe9b9ecef23ba8c4d8abbe5
sha1: c7559e2c1f349dd7e1499d2b7f4dd42909d22ae6
sha256: 36a9c7e15713611fd30bb98777ef3e01c7d31059cbd925b9b7a8ddfca12fb13c
sha512: 983dce7d868e7a6b75b7733002c466c745b3be8add0af7bb1676516305901c3480bc5449768296d3acda7f3ecdbb1e8c063c6665b1db27111ae2a2736348ff81
ssdeep: 1536:c+a5ZRwx11oGmEWOBnzwu23EoKlBwP3yYXel3J:cJ+x11oVOB8TKlaP3bOJJ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14F430168AD252814E845147DF19BCB1381B7B3A0B4449A75744FD82EFFDD32FA562E03
sha3_384: 88452e5a666fff5c973c542bc60358141444869a833931a15a9954821bba7ca34d913aa210b39c2a7750e16142ba03ff
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fea also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Sugar.17
MalwarebytesRansom.Encoded01
SangforRansom.Win32.Cryptor.gen
K7AntiVirusTrojan ( 0058ac911 )
BitDefenderGen:Variant.Ransom.Sugar.17
K7GWTrojan ( 0058ac911 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan-Ransom.Win32.Cryptor.fea
AlibabaRansom:Win32/Cryptor.5c4e84bd
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
RisingRansom.Cryptor!8.10A9 (CLOUD)
Ad-AwareGen:Variant.Ransom.Sugar.17
SophosMal/Generic-S
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.434253847fe9b9ec
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
IkarusTrojan-Ransom.FileCrypter
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Ransom.Sugar.17
ZoneAlarmTrojan-Ransom.Win32.Cryptor.fea
GDataGen:Variant.Ransom.Sugar.17
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
McAfeeGenericRXQS-VX!434253847FE9
TACHYONRansom/W32.Enc.59392
VBA32BScope.TrojanRansom.Cryptor
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B222
TencentWin32.Trojan.Filecoder.Palm
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
BitDefenderThetaAI:Packer.456DD6081E
AVGWin32:Malware-gen
Cybereasonmalicious.47fe9b
AvastWin32:Malware-gen

How to remove Trojan-Ransom.Win32.Cryptor.fea?

Trojan-Ransom.Win32.Cryptor.fea removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment