Ransom Trojan

Trojan-Ransom.Win32.Cryptor.fef malicious file

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fef virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Trojan-Ransom.Win32.Cryptor.fef?


File Info:

name: DB69E196FA43106CF9B0.mlw
path: /opt/CAPEv2/storage/binaries/578920d91894cea76656c08da43232bb4c76cbbbc762da179245218861268453
crc32: 06C1CA2B
md5: db69e196fa43106cf9b07b753e5207bf
sha1: b68f5367f79cadaded31ad514c4211c50173cbaa
sha256: 578920d91894cea76656c08da43232bb4c76cbbbc762da179245218861268453
sha512: 733c6709e0fae2f51993f86d07ced62de8e60089f45a8a17b4b5f63e455ae8054d4dac95098b4ec20a39c4ba503577190a2be4f2c0f656e5b49c4bfb0b65f4ab
ssdeep: 1536:5u8zwBHegF7m/IlqGgtHaleBXmRnQ+zhwIA9R:z7FGgtHaYeQ8WIwR
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1164301E4AC30BAB3D98E4B767F4A2D1BC37E613841BDD76948B92446B4D71C33561213
sha3_384: 392823edb1bc3f2fa95d0c260e6dccf62b96346e41d15b6614ee35b7bd088327b122644664f7eeb58e32aa963c6c7a35
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fef also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Sugar.17
CylanceUnsafe
SangforRansom.Win32.Cryptor.gen
K7AntiVirusTrojan ( 0058ac911 )
BitDefenderGen:Variant.Ransom.Sugar.17
K7GWTrojan ( 0058ac911 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ransom.Sugar.17
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan-Ransom.Win32.Cryptor.fef
AlibabaRansom:Win32/FileCryptor.f8ad1ab5
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
RisingRansom.Cryptor!8.10A9 (CLOUD)
Ad-AwareGen:Variant.Ransom.Sugar.17
SophosMal/Generic-S
ZillyaTrojan.Cryptor.Win32.734
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.db69e196fa43106c
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
IkarusTrojan-Ransom.FileCrypter
AviraTR/Dropper.Gen
GridinsoftRansom.Win32.AI.sa
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
ZoneAlarmTrojan-Ransom.Win32.Cryptor.fef
GDataGen:Variant.Ransom.Sugar.17
TACHYONRansom/W32.Enc.59392
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
McAfeeGenericRXQS-VX!DB69E196FA43
MAXmalware (ai score=86)
VBA32BScope.TrojanRansom.Cryptor
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B222
YandexTrojan.Filecoder!SdOsZmFavOg
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
AVGWin32:Malware-gen
Cybereasonmalicious.6fa431
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Ransom.Win32.Cryptor.fef?

Trojan-Ransom.Win32.Cryptor.fef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment