Malware

Hoax.Cryptodef removal

Malware Removal

The Hoax.Cryptodef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Hoax.Cryptodef virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Exhibits behavior characteristic of Cryptowall ransomware
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Hoax.Cryptodef?


File Info:

crc32: 28FB2ACD
md5: 9e44560bb8938c3560420fe74b77e9a1
name: 9E44560BB8938C3560420FE74B77E9A1.mlw
sha1: c044c973d1c5e324aaf735ed41a6a82f0e9d712a
sha256: dca516d795a783842b633f310d0fa090fdf79e584b8cdef45a48d6fea0537ea7
sha512: a6ceca1b3c6a1bf5004c4f1d5df77c9604c39689d190d13e2c3169fe4884b9a91a6ad030139615e92f3bcb435fd90508177d0ccf1207c185210601fa888a1793
ssdeep: 6144:4PgkVYJtnsQyCzzNYDXIBlm8b+oEdhA8jhIqa:yp8CYBl3b9Ed68Na
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2013 Cortado AG
InternalName: TPAutoConnect
FileVersion: 8,8,476,2
CompanyName: Cortado AG
ProductName: TPAutoConnect
ProductVersion: 8,8,476,2
FileDescription: ThinPrint AutoConnect printer creation service
OriginalFilename: TPAutoConnSvc.exe
Translation: 0x0409 0x04b0

Hoax.Cryptodef also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004d65cd1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader17.64754
CynetMalicious (score: 100)
CAT-QuickHealRansom.Crowti.G4
ALYacTrojan.GenericKD.2927961
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWTrojan ( 004d65cd1 )
Cybereasonmalicious.bb8938
BaiduWin32.Trojan.Filecoder.j
CyrenW32/Zbot.JC.gen!Eldorado
SymantecRansom.Cryptodefense
ESET-NOD32Win32/Filecoder.CryptoWall.F
ZonerTrojan.Win32.37135
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Ransomware.Upatre-7602608-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.2927961
NANO-AntivirusTrojan.Win32.Dwn.dzhida
ViRobotTrojan.Win32.CryptoWall.367104.A
SUPERAntiSpywareRansom.CryptoWall/Variant
MicroWorld-eScanTrojan.GenericKD.2927961
TencentMalware.Win32.Gencirc.114c218e
Ad-AwareTrojan.GenericKD.2927961
SophosML/PE-A + Mal/Tinba-T
ComodoTrojWare.Win32.Ransom.Crowti.V@6a51xr
BitDefenderThetaGen:NN.ZexaF.34628.yq2@aa4Luiai
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMR1
McAfee-GW-EditionBehavesLike.Win32.Dropper.fh
FireEyeGeneric.mg.9e44560bb8938c35
EmsisoftTrojan.GenericKD.2927961 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Cryptodef.lo
AviraTR/Crypt.ZPACK.224911
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Upatre
AegisLabTrojan.Win32.Yakes.mC8N
GDataTrojan.GenericKD.2927961
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeVawtrak-FAZ!9E44560BB893
MAXmalware (ai score=100)
VBA32Hoax.Cryptodef
MalwarebytesVirus.Agent
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBER.SMR1
RisingTrojan.Spy.Win32.Crowti.gx (CLOUD)
YandexTrojan.Filecoder!Hpz0UzEnEVw
IkarusTrojan.Win32.Ponmocup
FortinetW32/Dridex.DD!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
Qihoo-360Win32/Rootkit.Generic.HxQByLUA

How to remove Hoax.Cryptodef?

Hoax.Cryptodef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment