Malware

What is “Application.Crypter.G”?

Malware Removal

The Application.Crypter.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Crypter.G virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Writes a potential ransom message to disk

How to determine Application.Crypter.G?


File Info:

name: 08480B91082666689BC6.mlw
path: /opt/CAPEv2/storage/binaries/d061a0cf01294d30bbab7b2453c172b04d2f9ce841c2589678b44783e8bee044
crc32: 532AA0D8
md5: 08480b91082666689bc63c5646319916
sha1: 68d0dd73426626d8bea4d3399e753209ef159fcc
sha256: d061a0cf01294d30bbab7b2453c172b04d2f9ce841c2589678b44783e8bee044
sha512: 24a1bf0efd911de3d282b90a793563d35472241804297d6b25b450b4849468900b5cc758f5adf1c84126f657045c6342e53a72d2366e9ea48992d009e786b4bc
ssdeep: 1536:uh03grsyj5Rk0gtUABJYSDVMxvk/NPo4hFCYftEDQD2Um2RJzeLIIK37eLuGf1s3:AgyjKBJqxc/tHFRRCIpeLwil8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175A3E036B7D76463CAA206310763A775D776A354330397C71B988E7EDDB22C3AD2A042
sha3_384: d5d3fa2dd1d5fdbcf601692a64092b267da7045fa48682614e6e38868bf6c82c8c9e5ffac52ac50414bc717dc80004da
ep_bytes: 83ec0c53555657c7442410e891400033
timestamp: 2004-02-07 17:26:28

Version Info:

0: [No Data]

Application.Crypter.G also known as:

LionicRiskware.Win32.Crypter.1!c
MicroWorld-eScanApplication.Crypter.G
FireEyeApplication.Crypter.G
McAfeeArtemis!08480B910826
CylanceUnsafe
ZillyaTool.Crypter.Win32.2930
SangforPUP.Win32.Presenoker.mt
AlibabaRiskWare:Win32/Crypter.33b802c9
CyrenW32/Filecoder.COOD-0386
TrendMicro-HouseCallTROJ_GEN.R002H07KR21
Kasperskynot-a-virus:UDS:RiskTool.Win32.Crypter.hr
BitDefenderApplication.Crypter.G
NANO-AntivirusRiskware.Win32.Crypter.dbygvd
SophosGeneric PUA GI (PUA)
Comodofls.noname@0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
EmsisoftApplication.Crypter.G (B)
GDataApplication.Crypter.G
JiangminRiskTool.Crypter.co
Antiy-AVLTrojan/Generic.ASMalwS.A403FC
GridinsoftRansom.Win32.Gen.sa
ArcabitApplication.Crypter.G
MicrosoftPUA:Win32/Presenoker
VBA32Trojan.FakeAlert
ALYacApplication.Crypter.G
MalwarebytesRiskWare.Crypter
YandexRiskware.Crypter!/OgSz7xWGSE
FortinetRiskware/Crypter
Cybereasonmalicious.108266

How to remove Application.Crypter.G?

Application.Crypter.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment