Ransom Trojan

What is “Trojan-Ransom.Win32.GenericCryptor.eoi”?

Malware Removal

The Trojan-Ransom.Win32.GenericCryptor.eoi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GenericCryptor.eoi virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Attempts to modify desktop wallpaper
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

api.blockcypher.com
hjhqmbxyinislkkt.1j9r76.top

How to determine Trojan-Ransom.Win32.GenericCryptor.eoi?


File Info:

crc32: 11BA5D94
md5: 7a3bca711c26e2822004f4cd13a58d87
name: 7A3BCA711C26E2822004F4CD13A58D87.mlw
sha1: c691b09c58aab819fc7ba4fd3b716374664972f6
sha256: 5424e0953a8e8d1ba4a6b9d23245619987d19682eea278bff36028cc0e521484
sha512: 4baf1c438bffc6c487f155c53ff2c886797998419f5460a28365cd85ee4b47a70f443149fc9351634ee183bd90ae06ca15a2360ce558c884d255b63d9bd22e84
ssdeep: 6144:V28A9PWXXmzmv8GeFg/18kSEk8r+zjqyuEUiNf:Q8kyXmTS18kSEkGGjtuEUiZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.GenericCryptor.eoi also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.4644313
FireEyeGeneric.mg.7a3bca711c26e282
ALYacTrojan.GenericKD.4644313
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.GenericCryptor.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005089571 )
BitDefenderTrojan.GenericKD.4644313
K7GWTrojan ( 005089571 )
Cybereasonmalicious.11c26e
BitDefenderThetaGen:NN.ZedlaF.34590.cq4@aysPe5b
CyrenW32/Cerber.WJUF-4543
SymantecRansom.Cerber
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-6987218-0
KasperskyTrojan-Ransom.Win32.GenericCryptor.eoi
AlibabaRansom:Win32/Cerber.165749ba
NANO-AntivirusTrojan.Win32.DMKF.emmkvr
RisingRansom.Cerber!8.3058 (CLOUD)
Ad-AwareTrojan.GenericKD.4644313
EmsisoftTrojan-Ransom.Cerber (A)
ComodoMalware@#1xk1xy5dm3dvx
F-SecureTrojan.TR/Golroted.iejsd
DrWebTrojan.Encoder.10464
ZillyaTrojan.GenericKD.Win32.32617
TrendMicroRansom_CERBER.F117CG
McAfee-GW-EditionBehavesLike.Win32.ICLoader.dc
SophosMal/Cerber-Z
eGambitGeneric.Malware
AviraHEUR/AGEN.1116898
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Injector
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Cerber!rfn
ArcabitTrojan.Generic.D46DDD9
AhnLab-V3Trojan/Win32.Cerber.R196650
ZoneAlarmTrojan-Ransom.Win32.GenericCryptor.eoi
GDataTrojan.GenericKD.4644313
CynetMalicious (score: 100)
McAfeeArtemis!7A3BCA711C26
TACHYONRansom/W32.Cerber.237519
MalwarebytesMalware.AI.3535165494
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBER.F117CG
TencentWin32.Trojan.Raas.Auto
YandexTrojan.Injector!LU2nnlhhDpE
IkarusTrojan-Ransom.Cerber
FortinetW32/Injector.DMKF!tr
WebrootW32.Ransom.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Generic.HyoDiwcA

How to remove Trojan-Ransom.Win32.GenericCryptor.eoi?

Trojan-Ransom.Win32.GenericCryptor.eoi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment