Ransom Trojan

Trojan-Ransom.Win32.GenericCryptor.gag removal

Malware Removal

The Trojan-Ransom.Win32.GenericCryptor.gag is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GenericCryptor.gag virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.GenericCryptor.gag?


File Info:

crc32: 61B51A9F
md5: 4c69be342f08756ad1a6892a199a633e
name: 4C69BE342F08756AD1A6892A199A633E.mlw
sha1: d9e808a0e869445e1b311b8868b5ba30c6107d5e
sha256: 88114ad5b70deb632debb49f98d562cbaf6edc5765676a8cf6c0da8a0fdc78d6
sha512: c7c9fbb7cf7b131e3ab958ffd86fbb578b2db17e022d2954ecce7da8c7f515e26bf93b036c82f6b1136bb33cb801f658b44cf89b6df106a1469551206c3f7d46
ssdeep: 6144:H28A9Mmeh5PNJTEM9akV3jt95bx3nzBUM:W8LnQk9jlbRzBl
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.GenericCryptor.gag also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0050885a1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10464
CynetMalicious (score: 100)
ALYacTrojan.Generic.20506584
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.66620
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Injector.0fd0d3ad
K7GWTrojan ( 0050885a1 )
Cybereasonmalicious.42f087
CyrenW32/Cerber.LHNA-7575
SymantecRansom.Cerber
ESET-NOD32a variant of Win32/Injector.DMLC
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-6987220-0
KasperskyTrojan-Ransom.Win32.GenericCryptor.gag
BitDefenderTrojan.Generic.20506584
NANO-AntivirusTrojan.Win32.DMLC.emmdfe
MicroWorld-eScanTrojan.Generic.20506584
TencentWin32.Trojan.Raas.Auto
SophosML/PE-A + Mal/Cerber-Z
ComodoMalware@#276ms94r05flk
BitDefenderThetaGen:NN.ZedlaF.34608.cq4@aGJ!Bdk
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PBH21
McAfee-GW-EditionBehavesLike.Win32.ICLoader.dc
FireEyeGeneric.mg.4c69be342f08756a
EmsisoftTrojan-Ransom.Cerber (A)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1116898
eGambitGeneric.Malware
KingsoftWin32.Troj.Generic.v.(kcloud)
MicrosoftRansom:Win32/Cerber!rfn
ArcabitTrojan.Generic.D138E7D8
AegisLabTrojan.Win32.GenericCryptor.j!c
GDataTrojan.Generic.20506584
TACHYONRansom/W32.Cerber.236317
AhnLab-V3Trojan/Win32.Cerber.R196732
McAfeeArtemis!4C69BE342F08
MAXmalware (ai score=85)
VBA32Hoax.GenericCryptor
MalwarebytesMalware.AI.3487788223
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PBH21
RisingRansom.Cerber!8.3058 (CLOUD)
YandexTrojan.Injector!YVeOSF8MKqo
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DMTB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HyoDp9sA

How to remove Trojan-Ransom.Win32.GenericCryptor.gag?

Trojan-Ransom.Win32.GenericCryptor.gag removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment