Ransom Trojan

Trojan-Ransom.Win32.GenericCryptor.hgu information

Malware Removal

The Trojan-Ransom.Win32.GenericCryptor.hgu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.GenericCryptor.hgu virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.GenericCryptor.hgu?


File Info:

crc32: 8EE60C29
md5: 7223db4c7837e223efa809b095d8f25f
name: 7223DB4C7837E223EFA809B095D8F25F.mlw
sha1: 03d9c29fc9ee67c40137fb091b9aae7691378a2a
sha256: d49877e3b388ce6b6d1075b6840e24f7554c9bd79e3e5a6867a4ce55b99d7f9f
sha512: 49144f3db7a9e9a353994c3051fd335088f52a9fb2895d34d3b0d6d3698e5d0015270a8e5162cd7c284c1bc4b945b14599da4de0d708158ac51ea5debe5b1a89
ssdeep: 6144:T28A9pWBcw97412+aAQ+JuG1wbJwfwNgrb2qMCwxVfcugdxycWy6TI:y8GWP41frl1XfwNQ2qMb+yty6s
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.GenericCryptor.hgu also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005088071 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10464
CynetMalicious (score: 100)
CAT-QuickHealRansom.NSIS.Cerber.C
ALYacGen:Variant.Graftor.360906
CylanceUnsafe
ZillyaTrojan.GenericCryptor.Win32.4738
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.fb4d0f25
K7GWTrojan ( 005088071 )
Cybereasonmalicious.c7837e
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-6992030-0
KasperskyTrojan-Ransom.Win32.GenericCryptor.hgu
BitDefenderGen:Variant.Graftor.360906
NANO-AntivirusTrojan.Win32.DMIV.emiegb
MicroWorld-eScanGen:Variant.Graftor.360906
TencentWin32.Trojan.Genericcryptor.Aedv
SophosML/PE-A + Mal/Cerber-Z
ComodoMalware@#3no4ek4pb38jv
BitDefenderThetaGen:NN.ZedlaF.34628.lq4@ayIjQPl
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GK720
McAfee-GW-EditionBehavesLike.Win32.Vopak.dc
FireEyeGeneric.mg.7223db4c7837e223
EmsisoftTrojan-Ransom.Cerber (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1116898
eGambitGeneric.Malware
MicrosoftRansom:Win32/Cerber!rfn
ArcabitTrojan.Graftor.D581CA
AegisLabTrojan.Win32.GenericCryptor.j!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Graftor.360906
TACHYONRansom/W32.Cerber.285087
AhnLab-V3Trojan/Win32.Cerber.R196649
McAfeeArtemis!7223DB4C7837
MAXmalware (ai score=83)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0GK720
RisingRansom.Cerber!8.3058 (CLOUD)
IkarusTrojan.Win32.Filecoder
FortinetW32/Injector.DMIV!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Trojan.Ransom.f8a

How to remove Trojan-Ransom.Win32.GenericCryptor.hgu?

Trojan-Ransom.Win32.GenericCryptor.hgu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment