Trojan

Trojan.Win32.Cryprar.vh removal

Malware Removal

The Trojan.Win32.Cryprar.vh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.vh virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.vh?


File Info:

name: 53174F7AA7D7E1643935.mlw
path: /opt/CAPEv2/storage/binaries/3e22322c7ab5bcbc11756f12ef4ea0c3ceb8a2124c03d31ca1e00434e9ca4582
crc32: 0377B14F
md5: 53174f7aa7d7e1643935f8cc7532ff49
sha1: 8248d84ba3830ab4b4e2c92ff168cefce18d12d6
sha256: 3e22322c7ab5bcbc11756f12ef4ea0c3ceb8a2124c03d31ca1e00434e9ca4582
sha512: 9923bf60d8285f91824093f36749077ba92c8b96ace10ebd2c6eb079d69b38687221b688d774b41da37fa0b90e366607628aa1d03befba59ceedd00c98c718e4
ssdeep: 24576:5HLmCiIhiX8T90j4D9M6n9z4daDY0XOHpA1IZa:qpq9MG9EdaM0XOJ+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A251202B9C098B2D47219361E356B1169797C201F28CFDFA3F4AA6DDA314D1BA35B73
sha3_384: 62365f3d7277431ea29f8ddffb1beef9a6c6a6812508fe2cf3172e7297b963886713acceb1f8264bf93ac68c6bce8b4a
ep_bytes: e884040000e988feffff3b0d68d64300
timestamp: 2020-06-25 10:38:24

Version Info:

0: [No Data]

Trojan.Win32.Cryprar.vh also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Cryprar.4!c
MicroWorld-eScanTrojan.GenericKD.38126074
FireEyeGeneric.mg.53174f7aa7d7e164
ALYacTrojan.GenericKD.38126074
MalwarebytesTrojan.Dropper
SangforTrojan.Win32.Cryprar.gen
AlibabaTrojan:Win32/Cryprar.05dce379
K7GWTrojan ( 00581bcf1 )
K7AntiVirusTrojan ( 00581bcf1 )
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DQ
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002H0CKS21
Paloaltogeneric.ml
KasperskyTrojan.Win32.Cryprar.vh
BitDefenderTrojan.GenericKD.38126074
TencentWin32.Trojan.Cryprar.Ssgt
Ad-AwareTrojan.GenericKD.38126074
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftTrojan.GenericKD.38126074 (B)
GDataTrojan.GenericKD.38126074
AviraTR/Agent.kattp
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Agent.1031056
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 99)
McAfeeArtemis!53174F7AA7D7
MAXmalware (ai score=84)
VBA32Trojan.Cryprar
APEXMalicious
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
PandaTrj/CI.A

How to remove Trojan.Win32.Cryprar.vh?

Trojan.Win32.Cryprar.vh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment