Ransom Trojan

Trojan-Ransom.Win32.Cryptor.fes malicious file

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fes is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fes virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings

How to determine Trojan-Ransom.Win32.Cryptor.fes?


File Info:

name: D3BC611BBFB5D6BD712D.mlw
path: /opt/CAPEv2/storage/binaries/1ec836133ef00ecc9747a3d5dd8851b8e00744cd9549f49386e9a89f610ccdd4
crc32: 4B5CB0B3
md5: d3bc611bbfb5d6bd712da1dcacd9fccf
sha1: 38d6a4234702fb547134f329c55fff884b1ef808
sha256: 1ec836133ef00ecc9747a3d5dd8851b8e00744cd9549f49386e9a89f610ccdd4
sha512: 985ad7d67a3460c752daab3753a7c33f6f957faf73d5dc8afd62db9bd4d172ffd308fdf9afd26323f2c8cd1815b7efdec90fffb71fc6235f25252315c199c765
ssdeep: 1536:tPtVTqtPBE9lBf4O+2Wpjdn2SHgM6R6JRtW:tnTqpB8EO+fpjd2RM6o
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19A43E11AEC1475E2C49D23783C9DDA3B947C335876245D9B8C8FBAA53E2A32D801F6D1
sha3_384: 43409964b645eedc5f566f7b5ddc7a930b8e413692a76780e3015651c5dbec1a145c74f1a08c89d5ac7640bcacb319a0
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fes also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Sugar-9938412-0
ALYacTrojan.Ransom.Filecoder
MalwarebytesRansom.Encoded01
SangforRansom.Win32.Cryptor.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0058ac911 )
K7AntiVirusTrojan ( 0058ac911 )
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Cryptor.fes
BitDefenderGen:Variant.Ransom.Sugar.17
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
RisingRansom.Cryptor!8.10A9 (CLOUD)
Ad-AwareGen:Variant.Ransom.Sugar.17
SophosMal/Generic-S
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.d3bc611bbfb5d6bd
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
IkarusTrojan-Ransom.FileCrypter
GDataGen:Variant.Ransom.Sugar.17
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Ransom.Sugar.17
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
McAfeeGenericRXQS-VX!D3BC611BBFB5
TACHYONRansom/W32.Enc.59392
VBA32BScope.TrojanRansom.Cryptor
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B222
TencentWin32.Trojan.Filecoder.Wrqi
YandexTrojan.Filecoder!QoZb5g45lBg
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
BitDefenderThetaAI:Packer.456DD6081E
AVGWin32:Malware-gen
Cybereasonmalicious.bbfb5d
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Ransom.Win32.Cryptor.fes?

Trojan-Ransom.Win32.Cryptor.fes removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment