Ransom Trojan

Should I remove “Trojan-Ransom.Win32.Cryptor.fec”?

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fec virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Trojan-Ransom.Win32.Cryptor.fec?


File Info:

name: B7127185E8FCAD830BD8.mlw
path: /opt/CAPEv2/storage/binaries/45f648dcc67a641b2fa8d095bc1747fdd9534f0e6a5b22a3d1415dc1bb570ed5
crc32: B8473DE7
md5: b7127185e8fcad830bd83ba0bfb34d9a
sha1: 718be91fb233c4535f67ee95f14b28b3f8701290
sha256: 45f648dcc67a641b2fa8d095bc1747fdd9534f0e6a5b22a3d1415dc1bb570ed5
sha512: 7675b0dd473a0b30bde3748880a978eaf2d68b166e3e29b7199ddc64ac7f19abc0fea0faba3408cee0a534970bc26ec44f427f78b731dc728592e83ce287c400
ssdeep: 1536:AqWk3hbuQh9W0K/RvcZFYcvBBaWP2QXrcvq:ArUAZNcZScqQ4vq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T127430214C5B16BA6C4777EB8CC02A65B10F4F66326888B0504BA2D75F6C73F953BB217
sha3_384: ebffad744fc7ad4eee54824429dbe3929937bb6711cfcabed55deb9db678b691e9ebda6a547394b29ed711c29ecd8ea8
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fec also known as:

LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
ALYacGen:Variant.Ransom.Sugar.17
MalwarebytesRansom.Encoded01
SangforRansom.Win32.Cryptor.gen
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Ransom.Sugar.17
K7GWTrojan ( 0058ac911 )
K7AntiVirusTrojan ( 0058ac911 )
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan-Ransom.Win32.Cryptor.fec
AlibabaRansom:Win32/FileCryptor.5d3a301d
RisingRansom.Cryptor!8.10A9 (CLOUD)
Ad-AwareGen:Variant.Ransom.Sugar.17
TACHYONRansom/W32.Enc.59392
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
ZillyaTrojan.Cryptor.Win32.730
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.b7127185e8fcad83
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Ransom.Sugar.17
GDataGen:Variant.Ransom.Sugar.17
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
McAfeeGenericRXQS-VX!B7127185E8FC
MAXmalware (ai score=82)
VBA32BScope.TrojanRansom.Cryptor
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B222
YandexTrojan.Filecoder!fLUNMH1X4qg
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
BitDefenderThetaAI:Packer.456DD6081E
AVGWin32:Malware-gen
Cybereasonmalicious.5e8fca
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Ransom.Win32.Cryptor.fec?

Trojan-Ransom.Win32.Cryptor.fec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment