Trojan

Trojan.Win32.Cryprar.rw information

Malware Removal

The Trojan.Win32.Cryprar.rw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.rw virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.rw?


File Info:

name: 9B061C31708436578A0F.mlw
path: /opt/CAPEv2/storage/binaries/ee782f0a9029b4f1946ceb4f24280564ec42ef9fcc68276b81b10bbf976a9831
crc32: D6270EA2
md5: 9b061c31708436578a0f07f943fa19cd
sha1: aa3cd43ca1770acc5fdf183c2284df9e1c30a09e
sha256: ee782f0a9029b4f1946ceb4f24280564ec42ef9fcc68276b81b10bbf976a9831
sha512: 374c85846de2ab8e4ff498afb6cf0542f570cca0e88a234cdac9cda2e498fa23986f338d75fba3c3f64892ca97db9ac06baff392bdda389b28f2fa395dd6b4c8
ssdeep: 49152:4unqJurtp2BdwL2Bt/Ll2FXUxeTjcGzxHnMXd:4KqJuHgdlBFwkxeXHBnMN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14FB5231179E194B2C0B2297541F99BB42A3D7D201F248EDFA3D0692F4F745C17A3ABB2
sha3_384: c34ec35bd85ac8b4d15e2ea0587763171feedf60e0338f6540bed52399ee8617b66c709e1b7cefceaf5abf7ff01f9f89
ep_bytes: e828050000e988feffff3b0d58254300
timestamp: 2021-06-11 09:16:54

Version Info:

0: [No Data]

Trojan.Win32.Cryprar.rw also known as:

BkavW32.AIDetect.malware2
CAT-QuickHealTrojan.Cryprar
K7GWTrojan ( 0057bde51 )
K7AntiVirusTrojan ( 0057bde51 )
CyrenW32/Agent.DSN.gen!Eldorado
ESET-NOD32RAR/Agent.DJ
APEXMalicious
AvastSFX:Runner-C [Bd]
KasperskyTrojan.Win32.Cryprar.rw
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
FireEyeGeneric.mg.9b061c3170843657
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.Kryptik.TI4YEN
ZonerProbably Heur.RARAutorun
FortinetW32/RARAgent.DL!tr
AVGSFX:Runner-C [Bd]
Cybereasonmalicious.ca1770

How to remove Trojan.Win32.Cryprar.rw?

Trojan.Win32.Cryprar.rw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment