Malware

Application.Crypter.1 removal

Malware Removal

The Application.Crypter.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Crypter.1 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system

How to determine Application.Crypter.1?


File Info:

crc32: B8862CE2
md5: 11f026ec8250678eb6472c92c761e6e8
name: 11F026EC8250678EB6472C92C761E6E8.mlw
sha1: 96d85a420e9cbc789700b19abfbf01609504bd84
sha256: b72c70b8adb99b6d8e44521cb28bc8ab05ca1da85296097cd984064ebdf2f626
sha512: 471f19455de7aee08d7437be036dd9e4aa942838cafabd2bafa1b64a3f185184368f1e7dc7cf3ec37b5cf99ab9bcbf76817e3a5b1edd720473b9f98229dc59be
ssdeep: 24576:R0bV+clVd1l3N9U8V+RZRbtPgPJ/iN6C+oizTElyn:2LdhV+rLP+/iN6NTkO
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Application.Crypter.1 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Crypter.1
McAfeeGenericRXAA-AA!11F026EC8250
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 005386ec1 )
BitDefenderGen:Variant.Application.Crypter.1
K7GWSpyware ( 005386ec1 )
CrowdStrikewin/malicious_confidence_80% (D)
ArcabitTrojan.Application.Crypter.1
TrendMicroTROJ_GEN.R002C0RKF20
CyrenW32/Danabot.U.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-Banker.Win32.Danabot.gen
AlibabaTrojanSpy:Win32/Danabot.66b9a227
NANO-AntivirusTrojan.Win32.Danabot.fkdmdj
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.11b10f16
Ad-AwareGen:Variant.Application.Crypter.1
EmsisoftGen:Variant.Application.Crypter.1 (B)
F-SecureTrojan:W32/Danabot.A
InvinceaML/PE-A + Troj/Danabot-J
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.11f026ec8250678e
SophosTroj/Danabot-J
JiangminTrojan.Banker.Danabot.hc
AviraHEUR/AGEN.1115008
MAXmalware (ai score=72)
MicrosoftTrojan:Win32/Glupteba!ml
ZoneAlarmHEUR:Trojan-Banker.Win32.Danabot.gen
GDataGen:Variant.Application.Crypter.1
CynetMalicious (score: 100)
AhnLab-V3Malware/RL.Generic.R244112
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.Banker
ESET-NOD32a variant of Win32/Spy.Danabot.F
TrendMicro-HouseCallTROJ_GEN.R002C0RKF20
RisingSpyware.Danabot!8.FADB (TFE:6:QkvXVyDCawN)
FortinetW32/Danabot.F!tr
BitDefenderThetaAI:Packer.8E5C089E19
AVGWin32:BankerX-gen [Trj]
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.BO.9a5

How to remove Application.Crypter.1?

Application.Crypter.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment