Malware

Crypt.37 (B) (file analysis)

Malware Removal

The Crypt.37 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Crypt.37 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Armenian
  • Anomalous binary characteristics

How to determine Crypt.37 (B)?


File Info:

crc32: 2E705CD8
md5: 8c5da2d63c0b41071b9b366a37937653
name: 8C5DA2D63C0B41071B9B366A37937653.mlw
sha1: f1f5d418103d6e897183c85fad87f5da9579c27a
sha256: 9ba89c567051d7d43344468b0ce1705f5a3a2975754825d22aa864444d8b489d
sha512: 1319b487fc75bf8048ad3e4a934950df02d1cb549fbdb377feec6bbddd1aa3b1564c6056a383895e4ee8ef7d7e113a5d63f6e7dfa4fff4f0ac9c904546c8051d
ssdeep: 12288:hMMW8rCOn1Jv4OzfkkwDCV2PyDFwXQQF:WMWnIt4OjkkwDHX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2002-2004
InternalName: CameraMonitor
FileVersion: 1, 0, 1, 2
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: CameraMonitor Application
SpecialBuild:
ProductVersion: 1, 0, 1, 2
FileDescription: CameraMonitor MFC Application
OriginalFilename: CameraMonitor.EXE
Translation: 0x0409 0x04b0

Crypt.37 (B) also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Encoder.13570
CynetMalicious (score: 85)
ALYacGen:Variant.Crypt.37
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/generic.ali2000027
Cybereasonmalicious.63c0b4
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Locky.M
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Locky.aaxt
BitDefenderGen:Variant.Crypt.37
NANO-AntivirusTrojan.Win32.Locky.etqzra
ViRobotTrojan.Win32.R.Agent.641024
MicroWorld-eScanGen:Variant.Crypt.37
TencentWin32.Trojan.Filecoder.Ecav
Ad-AwareGen:Variant.Crypt.37
SophosMal/Generic-S
ComodoMalware@#2id4foab8n8cd
BitDefenderThetaGen:NN.ZexaF.34628.Ny0@aeg@hDgO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_LOCKY.SMALY0
McAfee-GW-EditionRansomware-GHR!8C5DA2D63C0B
FireEyeGeneric.mg.8c5da2d63c0b4107
EmsisoftGen:Variant.Crypt.37 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Locky.dov
AviraHEUR/AGEN.1120910
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Locky.A
ArcabitTrojan.Crypt.37
AegisLabTrojan.Win32.Locky.j!c
GDataGen:Variant.Crypt.37
AhnLab-V3Win-Trojan/RansomCrypt.Gen
McAfeeRansomware-GHR!8C5DA2D63C0B
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_LOCKY.SMALY0
RisingRansom.Locky!1.AE2C (CLOUD)
YandexTrojan.GenAsa!NycOs85ROZs
IkarusTrojan.Win32.Filecoder
FortinetW32/Locky.AZKQ!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Locky.HxQBL8AA

How to remove Crypt.37 (B)?

Crypt.37 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment