We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Win32/Crowti
Aliases: Dropper/Win32.Necurs (AhnLab) Trojan-Ransom.Win32.Cryptodef.iu (Kaspersky) Trojan horse Inject2.AHNI (AVG) TR/Crypt.Xpack.64673 (Avira) Trojan.Encoder.514 (Dr.Web) W32/Cryptodef.AHIO!tr (Fortinet) PWSZbot-FBKQ!86B6EE398F44 (McAfee) Troj/Agent-AHIO (Sophos) TSPY_ZBOT.SMCC (Trend Micro) Cryptowall (other) Cryptodefense (other)
Summary
Microsoft Defender Antivirus detects and removes this threat.
This threat can perform a number of actions of a malicious actor's choice on your device.
Devices affected by this threat might exhibit the following unexpected behavior in your device:
- Slow performance
- Presence of added or modified files
- Changes in desktop settings
- Freezing or crashing
- Diminished storage space