Malware

What is “Win32:MalOb-FE [Cryp]”?

Malware Removal

The Win32:MalOb-FE [Cryp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:MalOb-FE [Cryp] virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine Win32:MalOb-FE [Cryp]?


File Info:

crc32: C28BB5AC
md5: 506ae20f702265a62c2302623a395c0d
name: 506AE20F702265A62C2302623A395C0D.mlw
sha1: 684aa3ef13a71b67385ace5340b28416b4670f73
sha256: f43404f6d0d701aa25cfb53ce560773b213c99e215752f5a419aa3475a738c5e
sha512: 727bd5231ce6941aaabc03fbd325d7da3a4f39309282c460bd656d348ae2381c0a56fdd98bf591abb76cb2c5247dee7589d51c2ab56ede484ef04e4251291464
ssdeep: 6144:PHJF1eIi8b6j1AkDxcngdgoTF6GX2hKXB/8CQIgvri8CYVcnoACqzMoA36boLJp:fRi46ZcguNGmI8ZIUriPsOs60
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2013 Simon Tatham.
InternalName: PuTTY
FileVersion: Release 0.63
CompanyName: Simon Tatham
ProductName: PuTTY suite
ProductVersion: Release 0.63
FileDescription: SSH, Telnet and Rlogin client
OriginalFilename: PuTTY
Translation: 0x0809 0x04b0

Win32:MalOb-FE [Cryp] also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.TP.Eq0@bq6dgTci
FireEyeGeneric.mg.506ae20f702265a6
CAT-QuickHealTrojan.Swrort.A
ALYacGen:Trojan.Heur.TP.Eq0@bq6dgTci
CylanceUnsafe
VIPRETrojan.Win32.Swrort.B (v)
AegisLabTrojan.Win32.Generic.m!c
SangforMalware
K7AntiVirusTrojan ( 0055e3f11 )
BitDefenderGen:Trojan.Heur.TP.Eq0@bq6dgTci
K7GWTrojan ( 0055e3f11 )
Cybereasonmalicious.f70226
CyrenW32/Rozena.B.gen!Eldorado
SymantecBackdoor.Trojan
APEXMalicious
AvastWin32:MalOb-FE [Cryp]
ClamAVWin.Exploit.Countdown-1
KasperskyHEUR:Backdoor.Win32.Generic
AlibabaBackdoor:Win32/Leivion.536bd52e
NANO-AntivirusTrojan.Win32.Swrort.uhpfc
Ad-AwareGen:Trojan.Heur.TP.Eq0@bq6dgTci
SophosMal/Generic-R + Mal/Swrort-D
ComodoTrojWare.Win32.Rozena.A@4jwdqr
F-SecureTrojan.TR/Patched.Gen2
DrWebTrojan.Swrort.1
TrendMicroTROJ_GEN.R007C0DAR21
McAfee-GW-EditionSwrort.d
EmsisoftGen:Trojan.Heur.TP.Eq0@bq6dgTci (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Patched.Gen2
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Leivion.I
ArcabitTrojan.Heur.TP.E763BF
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataGen:Trojan.Heur.TP.Eq0@bq6dgTci
CynetMalicious (score: 100)
Acronissuspicious
McAfeeSwrort.d
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Rozena.ED
TrendMicro-HouseCallTROJ_GEN.R007C0DAR21
RisingHackTool.Swrort!1.6477 (CLASSIC)
YandexWin32.Swrort.Gen.2
IkarusTrojan.Win32.Rozena
FortinetW32/Swrort.C!tr
BitDefenderThetaAI:Packer.F6F5D92E1F
AVGWin32:MalOb-FE [Cryp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Leivion.HxQBBS8A

How to remove Win32:MalOb-FE [Cryp]?

Win32:MalOb-FE [Cryp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment