Ransom Trojan

How to remove “Trojan-Ransom.Win32.Cryptor”?

Malware Removal

The Trojan-Ransom.Win32.Cryptor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor virus can do?

  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (255 unique times)
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Cryptor?


File Info:

crc32: 3F2C60CF
md5: 8e952d2186e946cfa1122595c17f4c7d
name: 8E952D2186E946CFA1122595C17F4C7D.mlw
sha1: 6f42c15c43497b79ce5e0ebb61bb68a8649d9bd7
sha256: a5751a46768149c5ddf318fd75afc66b3db28a5b76254ee0d6ae27b21712e266
sha512: 1f33aba6a34401f0aa26553312782e71644aeb99bab4841906eaa1318387d99f3676bdd221b4431990faf54db8887458a43ade5ff9334e36cc39f3c94b9d0b95
ssdeep: 3072:oiyQ0uz/c8p7Ua3ZstuiSNFYD7RMf+HgrIqra5FqTbK+WRivbrwi:mQ0uzz3OAiSNFYvRXHjTFj+TEi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor also known as:

McAfeeRDN/Ransom
AegisLabTrojan.Multi.Generic.4!c
SangforRansom.Win32.Cryptor.gen
BitDefenderTrojan.GenericKD.45742277
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D2B9F8C5
CyrenW32/Trojan.ENNK-0494
SymantecTrojan.Gen.2
AvastWin32:Malware-gen
CynetMalicious (score: 85)
KasperskyHEUR:Trojan-Ransom.Win32.Cryptor.gen
AlibabaRansom:Win32/Cryptor.668d47ca
ViRobotTrojan.Win32.S.Conti.195072
MicroWorld-eScanTrojan.GenericKD.45742277
Ad-AwareTrojan.GenericKD.45742277
SophosMal/Generic-S + Troj/Ransom-GEU
ComodoMalware@#zgjk1km3ifml
F-SecureTrojan.TR/Ransom.WM
DrWebTrojan.Encoder.33482
TrendMicroTrojan.Win32.MALREP.THBAGBA
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.8e952d2186e946cf
EmsisoftTrojan.GenericKD.45742277 (B)
WebrootW32.Trojan.AAA5
AviraTR/Ransom.WM
MAXmalware (ai score=99)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AAA5
ZoneAlarmHEUR:Trojan-Ransom.Win32.Cryptor.gen
GDataTrojan.GenericKD.45742277
ALYacTrojan.Ransom.Conti
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.MALREP.THBAGBA
RisingRansom.Cryptor!8.10A9 (TFE:6:NeZu2qeHMuH)
IkarusTrojan-Ransom.Conti
FortinetPossibleThreat.ARN.M
BitDefenderThetaGen:NN.ZedlaF.34574.lu4@aO6XMrni
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.Hx4CVjUA

How to remove Trojan-Ransom.Win32.Cryptor?

Trojan-Ransom.Win32.Cryptor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment