Ransom Trojan

How to remove “Trojan-Ransom.Win32.Cryptor.fej”?

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fej is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fej virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Trojan-Ransom.Win32.Cryptor.fej?


File Info:

name: 9582DFAC3594F2C7A3B7.mlw
path: /opt/CAPEv2/storage/binaries/3c3308db5798a5b1148d0698437c915bd288111a081563070d006280b999ea82
crc32: E2B98347
md5: 9582dfac3594f2c7a3b7831820d358d2
sha1: af4750f3e151d2655df781e63adce62dcefdf2c6
sha256: 3c3308db5798a5b1148d0698437c915bd288111a081563070d006280b999ea82
sha512: 1819499e9eb779bbebcd6ef90e964f8c126ce7d7ba4e62c46dd5507894dd8da6ae6976120e2edfe3d0b76c7f44cdf30dc66c579a2f506315a301603a12720186
ssdeep: 1536:V+fK1XfGZPqgLnGzPtNgVNLPPY/ByUPY0pfFgmJQ:h1v6qUGTqNL3SJQ0pfS
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1844302886DB1C5B6C9EF25FDF65FD921E66EDF2055A0131704963B0E374C22332ABA42
sha3_384: 3defcb5dc930e608847e2e9ba35fd2f331c43f3c84b7c6e37bc943cb42376f2a992e8d81854e756e74afafe545a25a33
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fej also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
FireEyeGeneric.mg.9582dfac3594f2c7
McAfeeGenericRXQS-VX!9582DFAC3594
CylanceUnsafe
ZillyaTrojan.Cryptor.Win32.738
SangforRansom.Win32.Cryptor.fej
K7AntiVirusTrojan ( 0058ac911 )
AlibabaRansom:Win32/FileCryptor.7b89ea5b
K7GWTrojan ( 0058ac911 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.456DD6081E
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
TrendMicro-HouseCallTROJ_FRS.0NA103B222
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan-Ransom.Win32.Cryptor.fej
BitDefenderGen:Variant.Ransom.Sugar.17
TencentWin32.Trojan.Filecoder.Htlq
Ad-AwareGen:Variant.Ransom.Sugar.17
TACHYONRansom/W32.Enc.59392
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
SophosMal/Generic-S
Paloaltogeneric.ml
GDataWin32.Trojan.Agent.HERXRB
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
GridinsoftRansom.Win32.AI.sa
ZoneAlarmTrojan-Ransom.Win32.Cryptor.fej
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
VBA32BScope.TrojanRansom.Cryptor
ALYacGen:Variant.Ransom.Sugar.17
MAXmalware (ai score=87)
MalwarebytesRansom.Encoded01
APEXMalicious
RisingRansom.Cryptor!8.10A9 (CLOUD)
YandexTrojan.Filecoder!2Z2/qvpyiL8
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
AVGWin32:Malware-gen
Cybereasonmalicious.c3594f
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Ransom.Win32.Cryptor.fej?

Trojan-Ransom.Win32.Cryptor.fej removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment