Ransom Trojan

Trojan-Ransom.Win32.SageCrypt.fjk removal

Malware Removal

The Trojan-Ransom.Win32.SageCrypt.fjk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.SageCrypt.fjk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.SageCrypt.fjk?


File Info:

crc32: B4D53FFE
md5: 9b163a5ca8bdb527de702718ce487383
name: upload_file
sha1: 8830a08089cec18587c202e3adfc25940a40eace
sha256: 929dea381136f491a6b9e291182835ab8d9b190614fed258d744cac0939aada4
sha512: 8fff3d22c83290dd4dd7b9015ea319a498797c2e4ae9fe1acbf1481706d898541068c3994b799d8b83f0ebe4edac904ca7e684515fd3cf20995c52ad09aa4b46
ssdeep: 6144:b2EDYH4aaPx2v909HPNvg/7K4GHTOmVcdKsXv5o7bKSMwaM0hY:CV5l09lg/7HGqmm0sXv5gKSMwaM0hY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.SageCrypt.fjk also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43557469
FireEyeGeneric.mg.9b163a5ca8bdb527
McAfeeArtemis!9B163A5CA8BD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0050b2d01 )
BitDefenderTrojan.GenericKD.43557469
K7GWTrojan ( 0050b2d01 )
Cybereasonmalicious.ca8bdb
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.SageCrypt.fjk
AlibabaRansom:Win32/generic.ali2000010
AegisLabTrojan.Win32.Malicious.4!c
TencentMalware.Win32.Gencirc.10bbe17d
Ad-AwareTrojan.GenericKD.43557469
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1115437
DrWebTrojan.Encoder.32240
ZillyaTrojan.SageCrypt.Win32.204
TrendMicroMal_MiliCry-2t
FortinetW32/Kryptik.GPRG!tr
EmsisoftTrojan.GenericKD.43557469 (B)
SentinelOneDFI – Suspicious PE
JiangminTrojan.SageCrypt.gg
AviraHEUR/AGEN.1115437
MAXmalware (ai score=85)
Antiy-AVLTrojan[Ransom]/Win32.SageCrypt
ArcabitTrojan.Generic.D298A25D
ZoneAlarmTrojan-Ransom.Win32.SageCrypt.fjk
MicrosoftTrojan:Win32/Ymacco.AA92
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R346410
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34142.zOW@aq5KsDfi
ALYacTrojan.GenericKD.43557469
TACHYONRansom/W32.SageCrypt.416256
VBA32Hoax.SageCrypt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.GPRG
TrendMicro-HouseCallMal_MiliCry-2t
RisingStealer.Delf!8.415 (CLOUD)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKD.43557469
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM10.1.62C2.Malware.Gen

How to remove Trojan-Ransom.Win32.SageCrypt.fjk?

Trojan-Ransom.Win32.SageCrypt.fjk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment