Ransom Trojan

About “Trojan-Ransom.Win32.Cryptor.fem” infection

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fem is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fem virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Manipulates data from or to the Recycle Bin
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Writes a potential ransom message to disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to modify proxy settings

How to determine Trojan-Ransom.Win32.Cryptor.fem?


File Info:

name: 75EF2E9F469D9B470022.mlw
path: /opt/CAPEv2/storage/binaries/b6c27f687fbb1b0e6a45bade47a843e34896934624c3130a63a787b50df149ed
crc32: 69201A05
md5: 75ef2e9f469d9b4700228aef41a4833f
sha1: 10f76c0fdee991d7f2d1b183c33b2b9b8a8c0bd9
sha256: b6c27f687fbb1b0e6a45bade47a843e34896934624c3130a63a787b50df149ed
sha512: 114d295f8d7f76305dc4c529f619749220b6745e904dc462585bc1aa33849950093901a49a328aeadae1e268673b5c762ba662571e086e9635e1dbc39d504f45
ssdeep: 1536:R7wvk47GDb7lSsijjkO9VLZf2LPTfuSJii:R7QCPlDijj5VtfAPjuGii
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19C4302D5EFA636F1D5451DB210961E339B13431078A8FAFA6EED27033D905E352B0646
sha3_384: d6d8ae21ecc4ee5ee2eb979abcb90b84424db3f61f4fa09882c2bb7bbac003f7c6523bd2d62499210aedc911db5bc635
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fem also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
SangforRansom.Win32.Cryptor.gen
K7AntiVirusTrojan ( 0058ac911 )
BitDefenderGen:Variant.Ransom.Sugar.17
K7GWTrojan ( 0058ac911 )
Cybereasonmalicious.f469d9
BitDefenderThetaAI:Packer.456DD6081E
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan-Ransom.Win32.Cryptor.fem
AlibabaRansom:Win32/generic.ali2000010
RisingRansom.Cryptor!8.10A9 (CLOUD)
Ad-AwareGen:Variant.Ransom.Sugar.17
TACHYONRansom/W32.Enc.59392
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.75ef2e9f469d9b47
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
GDataGen:Variant.Ransom.Sugar.17
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Ransom.Sugar.17
ZoneAlarmTrojan-Ransom.Win32.Cryptor.fem
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
McAfeeGenericRXQS-VX!75EF2E9F469D
MAXmalware (ai score=89)
VBA32BScope.TrojanRansom.Cryptor
MalwarebytesRansom.Encoded01
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B222
TencentWin32.Trojan.Filecoder.Ajvz
YandexTrojan.Filecoder!3AtPpO6PUO0
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Ransom.Win32.Cryptor.fem?

Trojan-Ransom.Win32.Cryptor.fem removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment