Ransom Trojan

What is “Trojan-Ransom.Win32.Cryptor.fed”?

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fed is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fed virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Trojan-Ransom.Win32.Cryptor.fed?


File Info:

name: 9D7B26D6158B606394B2.mlw
path: /opt/CAPEv2/storage/binaries/7b8d16ac80f385961065c6b058ae16a08ed7258b4acd6039c8025aac528ce200
crc32: EC2DFC7B
md5: 9d7b26d6158b606394b2238e570ffdd4
sha1: 45eeaf8622140f6b1668e7008a34242e39d6fd97
sha256: 7b8d16ac80f385961065c6b058ae16a08ed7258b4acd6039c8025aac528ce200
sha512: e1a388f6410a2051b3852c67d19d945d7899d5c7e2611c7307f11d1370ca813103036a279009420f6bd524114f3a5835e860d12196c9ca441dcc810f55dfcbea
ssdeep: 768:/ED6FL9boHrCB+ijPvumZEkfKxdSzjW2Vso00Qkhd1XlcUJhdu//Yq6EQuVq:cD4LRaoudxd0We2khd1XZu76NuI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15F43F161AEA27A9CE7ED43FECCC796369531122053E12D77118E0F2A73817836B72472
sha3_384: 8774217cb30cd7d4ab3803996ef4db7ae34a378c4eb0c305e3c1f17859457278f1d0ada2e8df95d7430f25f63f8465ae
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fed also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Sugar-9938412-0
McAfeeGenericRXQS-VX!9D7B26D6158B
CylanceUnsafe
SangforRansom.Win32.Cryptor.gen
K7AntiVirusTrojan ( 0058ac911 )
BitDefenderGen:Variant.Ransom.Sugar.17
K7GWTrojan ( 0058ac911 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Cryptor.fed
AlibabaRansom:Win32/FileCryptor.a5da45f1
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
TencentWin32.Trojan.Filecoder.Hwcx
Ad-AwareGen:Variant.Ransom.Sugar.17
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.9d7b26d6158b6063
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
IkarusTrojan-Ransom.FileCrypter
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Ransom.Sugar.17
ZoneAlarmTrojan-Ransom.Win32.Cryptor.fed
GDataGen:Variant.Ransom.Sugar.17
TACHYONRansom/W32.Enc.59392
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
VBA32BScope.TrojanRansom.Cryptor
ALYacGen:Variant.Ransom.Sugar.17
MAXmalware (ai score=86)
MalwarebytesRansom.Encoded01
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B222
RisingRansom.Cryptor!8.10A9 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
BitDefenderThetaAI:Packer.456DD6081E
AVGWin32:Malware-gen
Cybereasonmalicious.6158b6
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Ransom.Win32.Cryptor.fed?

Trojan-Ransom.Win32.Cryptor.fed removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment