Trojan

Trojan.Win32.Cryprar.ug removal guide

Malware Removal

The Trojan.Win32.Cryprar.ug is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.ug virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.ug?


File Info:

name: 5515C5B329762CB6D8EC.mlw
path: /opt/CAPEv2/storage/binaries/0fde5aae58783e9cc523b579bcacc78e8454545b9b359abceddd0c1b4c77e097
crc32: FFB03DAC
md5: 5515c5b329762cb6d8ec119a764aecbe
sha1: 834ffb44e259998272f365efd207017454962319
sha256: 0fde5aae58783e9cc523b579bcacc78e8454545b9b359abceddd0c1b4c77e097
sha512: 30a3581f83ceb832e4e40c485efd4be40c5f0524decfe027fba2bc1f94cb26acc1bbdc70aaf9d508e55f436cc68498e808c5f0f538544cb7a3bfa15ec5314de2
ssdeep: 49152:IVBfJXAExDasRi8/jNpqWket+JYB9Pa351mYmtG:IVBfKExDVi8ZXkeSYzi350YmtG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2A52312F5C04472C4B2067198386BA45C3EB9701F649BEFBBF49C6D9F75182363A6A3
sha3_384: f9ed37d7ddb2e4b9e871f8cc4bb365f9c5c06f90dd69c0f6765ab0f99aceafa756ec45e993a92a17791c00143ef9d7d5
ep_bytes: e894040000e988feffff3b0d18d54300
timestamp: 2021-06-11 08:28:12

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 6.2.1
ProductVersion: 6.2.1
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2021
OriginalFilename: WinRAR.exe
Translation: 0x0409 0x04e4

Trojan.Win32.Cryprar.ug also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.47500860
FireEyeTrojan.GenericKD.47500860
McAfeeArtemis!5515C5B32976
K7AntiVirusTrojan ( 0057bde51 )
AlibabaTrojan:Win32/Cryprar.094e3aa2
K7GWTrojan ( 0057bde51 )
SymantecTrojan.Gen.2
ESET-NOD32RAR/Agent.DQ
AvastSFX:Runner-C [Bd]
KasperskyTrojan.Win32.Cryprar.ug
BitDefenderTrojan.GenericKD.47500860
NANO-AntivirusTrojan.Win32.Cryprar.jimepg
Ad-AwareTrojan.GenericKD.47500860
EmsisoftTrojan.GenericKD.47500860 (B)
DrWebTrojan.MulDrop19.7363
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S
Paloaltogeneric.ml
GDataTrojan.GenericKD.47500860
JiangminTrojan.Generic.haxnr
ArcabitTrojan.Generic.D2D4CE3C
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win.Generic.R456326
VBA32Trojan.Swrort
ALYacTrojan.GenericKD.47500860
MAXmalware (ai score=89)
MalwarebytesTrojan.Dropper.SFX
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002H0DKQ21
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
IkarusTrojan.Agent
AVGSFX:Runner-C [Bd]
PandaTrj/CI.A
MaxSecureTrojan.Malware.131210609.susgen

How to remove Trojan.Win32.Cryprar.ug?

Trojan.Win32.Cryprar.ug removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment