Malware

Win32:Crypt-LR [Trj] removal guide

Malware Removal

The Win32:Crypt-LR [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Crypt-LR [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:Crypt-LR [Trj]?


File Info:

name: F84257DA064C1B1CA4E0.mlw
path: /opt/CAPEv2/storage/binaries/d141f7aab03ccc4671e4faeed8e7e0ea65e76c3fb6558498180ab6c4e8d1edf1
crc32: 3C5472B8
md5: f84257da064c1b1ca4e05bc6c7fde242
sha1: adf24549b7691ead04a173f46967b9583a81b835
sha256: d141f7aab03ccc4671e4faeed8e7e0ea65e76c3fb6558498180ab6c4e8d1edf1
sha512: 99d9700aac5a41ac4bf7f6be075e71f9165a48e889ab913e8f518d1ca3894160a2dc1437171d4f0cefa8270c4d04c162091d4a772687653d0dcbfc8e891fe776
ssdeep: 6144:Ic//////d9/flbMuRLnq3i/8Dx0ZdZdBQ46LGGpN:Ic//////LSuFq3e8DxABQ5LGMN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9241293FC2D89F3EC1076BD6D5F09655DECAC6230D40D69AB25BC8ADBB6B80C814217
sha3_384: 5dae24d9fe7b3d6a4cc7a9da2332897855e3d7599858f34a81c28ae77dd01eb4816f26885a78c403907106f06cfdc0b5
ep_bytes: 558bec83c4f05356b8e4410010e83ae1
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32:Crypt-LR [Trj] also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Mint.Zard.35
FireEyeGeneric.mg.f84257da064c1b1c
SkyhighBehavesLike.Win32.HLLP.dc
McAfeeBackDoor-DOQ.gen.w
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.Mint.Zard.35
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000ca2d71 )
AlibabaTrojanDropper:Win32/Danseed.dfa54ef7
K7GWTrojan ( 000ca2d71 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.DnaSeed.a
VirITBackdoor.Win32.Pigeon.LRK
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.ErPack
APEXMalicious
TrendMicro-HouseCallTROJ_DRPR7.TOMA
ClamAVWin.Trojan.IRCBot-122
KasperskyTrojan-Dropper.Win32.Danseed.b
BitDefenderGen:Heur.Mint.Zard.35
NANO-AntivirusTrojan.Win32.Pigeon.whadd
AvastWin32:Crypt-LR [Trj]
TencentTrojan.Win32.Dropper.tta
EmsisoftGen:Heur.Mint.Zard.35 (B)
F-SecureTrojan.TR/Hijacker.Gen
DrWebBackDoor.Pigeon.72
ZillyaDropper.Danseed.Win32.442
TrendMicroTROJ_DRPR7.TOMA
Trapminemalicious.high.ml.score
SophosMal/Dropper-G
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Danseed.jw
GoogleDetected
AviraTR/Hijacker.Gen
VaristW32/Delf.gen!GSA
Antiy-AVLTrojan/Win32.Buzus.miux
KingsoftWin32.Hack.BaiXue.aa.33792
MicrosoftVirTool:Win32/DelfInject.gen!X
XcitiumTrojWare.Win32.TrojanDropper.ErPack@1f2g
ArcabitTrojan.Mint.Zard.35
ViRobotBackdoor.Win32.Delf.625152
ZoneAlarmTrojan-Dropper.Win32.Danseed.b
GDataGen:Heur.Mint.Zard.35
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C37520
BitDefenderThetaAI:Packer.403A28D01F
MAXmalware (ai score=99)
VBA32Trojan.Win32.Buzus.ao
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Zegost!1.66C4 (CLASSIC)
YandexTrojan.GenAsa!l8UDh1x9t5c
IkarusDownloader.Delphi
MaxSecureTrojan.Malware.22614.susgen
FortinetW32/Injector.fam!tr
AVGWin32:Crypt-LR [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Danseed.b

How to remove Win32:Crypt-LR [Trj]?

Win32:Crypt-LR [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment