Malware

How to remove “Generic.Cryptor.X.4ACD273F”?

Malware Removal

The Generic.Cryptor.X.4ACD273F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Cryptor.X.4ACD273F virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

ramzy.duckdns.org

How to determine Generic.Cryptor.X.4ACD273F?


File Info:

crc32: E3FC4283
md5: aa6794a31b8c3a039dcf70b5039fe7cb
name: AA6794A31B8C3A039DCF70B5039FE7CB.mlw
sha1: a5d8e0b6908cf678d4c452d3974153b9c8fb3194
sha256: 413d73ef75407d0fa7bc7dbfdf693e7de00b60d3d3d55b225234a2c0ea467c45
sha512: c873c14177446f283478328bf9f55a9300ad679d30c4ab432db43ebf2fc08f90cf4eb66e1ac95c314b418c9577b6c67f17f9ba4046235bcca5d4fa59cf9804a6
ssdeep: 12288:2iN/pHdfxKQcBYcXlB8eqy+yRgFqDU5V9dqdmXXr/ZTV7UZniUpElSV+0g3:2idNBlcicVBIJmAVfDN57UxiUpEI4B3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Cryptor.X.4ACD273F also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacGeneric.Cryptor.X.4ACD273F
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderGeneric.Cryptor.X.4ACD273F
ESET-NOD32a variant of Win32/GenKryptik.FIGR
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Backdoor.Win32.Remcos.gen
MicroWorld-eScanGeneric.Cryptor.X.4ACD273F
Ad-AwareGeneric.Cryptor.X.4ACD273F
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34050.IqZ@aaxlQjci
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.aa6794a31b8c3a03
EmsisoftGeneric.Cryptor.X.4ACD273F (B)
eGambitUnsafe.AI_Score_97%
MicrosoftTrojan:Win32/Woreflint.A!cl
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGeneric.Cryptor.X.4ACD273F
MAXmalware (ai score=84)
TrendMicro-HouseCallTROJ_GEN.R06CH09H221
RisingTrojan.Kryptik!1.D84E (CLASSIC)
Paloaltogeneric.ml
Qihoo-360HEUR/QVM20.1.FD66.Malware.Gen

How to remove Generic.Cryptor.X.4ACD273F?

Generic.Cryptor.X.4ACD273F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment