Ransom Trojan

Trojan-Ransom.Win32.GenericCryptor.esb information

Malware Removal

The Trojan-Ransom.Win32.GenericCryptor.esb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GenericCryptor.esb virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.GenericCryptor.esb?


File Info:

crc32: 0C8B31E3
md5: 1190090ccd616d042c7e3a07753e7b8a
name: 1190090CCD616D042C7E3A07753E7B8A.mlw
sha1: a7184a38a614ecd4f47c9c7612646fdd7a0894b3
sha256: 8bef299028d9df657bd32bb360d86f8c6cac0d1b3d62e00123bf35fe31d2e59d
sha512: 157730f2bbab6982e157164274a69d6189a79344d537f95ee183bec52e05ac923bb3ee57815da67607b1a0ae333552680361b5a8aa2a511009ac67c5015f0d09
ssdeep: 6144:V28A9PWXXmzmv8GeFg/18kSEk8r+zjqyuEUiNE:Q8kyXmTS18kSEkGGjtuEUia
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.GenericCryptor.esb also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005089571 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10464
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.32617
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.0b1dd11b
K7GWTrojan ( 005089571 )
Cybereasonmalicious.ccd616
CyrenW32/Cerber.WJUF-4543
SymantecRansom.Cerber
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-6987218-0
KasperskyTrojan-Ransom.Win32.GenericCryptor.esb
BitDefenderTrojan.GenericKD.4644313
NANO-AntivirusTrojan.Win32.DMKF.emmkvr
ViRobotTrojan.Win32.Z.Cerber.237519.CE
MicroWorld-eScanTrojan.GenericKD.4644313
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKD.4644313
SophosMal/Cerber-Z
ComodoMalware@#1xk1xy5dm3dvx
BitDefenderThetaGen:NN.ZedlaF.34608.cq4@aysPe5b
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.F117CH
McAfee-GW-EditionBehavesLike.Win32.ICLoader.dc
FireEyeGeneric.mg.1190090ccd616d04
EmsisoftTrojan-Ransom.Cerber (A)
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1116898
eGambitGeneric.Malware
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Cerber!rfn
ArcabitTrojan.Generic.D46DDD9
AegisLabTrojan.Win32.GenericCryptor.j!c
GDataTrojan.GenericKD.4644313
TACHYONRansom/W32.Cerber.237519
AhnLab-V3Trojan/Win32.Cerber.R196650
McAfeeArtemis!1190090CCD61
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3535165494
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBER.F117CH
RisingRansom.Cerber!8.3058 (CLOUD)
IkarusTrojan-Ransom.Cerber
FortinetW32/Injector.DMKF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HyoD2JsA

How to remove Trojan-Ransom.Win32.GenericCryptor.esb?

Trojan-Ransom.Win32.GenericCryptor.esb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment