Malware

About “Hoax.FileCryptor” infection

Malware Removal

The Hoax.FileCryptor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Hoax.FileCryptor virus can do?

  • Anomalous binary characteristics
  • Unusual version info supplied for binary

How to determine Hoax.FileCryptor?


File Info:

crc32: F043CBE1
md5: cc989b84cc4b5688931e20cc4a515887
name: CC989B84CC4B5688931E20CC4A515887.mlw
sha1: 25fe7ffe900f84bc67bb90b9ada4040a35df05f2
sha256: 946f2c19bdf5edd48bedf507d44466da678a7b2a44cf848e4c35d92a2738f16e
sha512: 9c2b895cd96262ec86824cec222b2fc1d4e74fc1104917c7207cbef6aceb6c5cef24d2762d6df1966f508eca3efa140183f96f02be4bdcf209abf58fafb997cd
ssdeep: 1536:8Qb2uO2dn34rhdPVr4BADbWJr+UFDbtxTn8PVYGX:SwZ4vif9Dbtxb8PVvX
type: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2018
Assembly Version: 1.2.13.5
InternalName: RansomDotZeroCMD.exe
FileVersion: 1.2.13.5
CompanyName: Rekt-Cheats.ML DigitalGroup LLC
LegalTrademarks:
Comments: RaaS RansomWare
ProductName: Ransom DotZero CMD.Ransom
ProductVersion: 1.2.13.5
FileDescription: Ransom DotZero CMD Ransom
OriginalFilename: RansomDotZeroCMD.exe

Hoax.FileCryptor also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicHacktool.Win64.FakeRansom.3!c
DrWebJoke.Runsom.1
ALYacTrojan.Ransom.DotZeroCMD
CylanceUnsafe
ZillyaTool.PXH.Win64.1
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRiskWare:Win64/FakeRansom.06a7399e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4cc4b5
SymantecTrojan.Gen.MBT
AvastWin64:Malware-gen
KasperskyHoax.Win64.FakeRansom.a
BitDefenderTrojan.Joke.PXH
MicroWorld-eScanTrojan.Joke.PXH
TencentWin64.Trojan-psw.Fakeransom.Tbim
Ad-AwareTrojan.Joke.PXH
SophosMal/Generic-R + Troj/DotZero-A
ComodoMalware@#2m8rnmp3nvcc4
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_DOTZERO.THDBCAH
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.Joke.PXH
EmsisoftTrojan.Joke.PXH (B)
WebrootW32.Trojan.Joke
AviraJOKE/Redcap.mrsrx
MicrosoftTrojan:Win32/Occamy.B
ArcabitTrojan.Joke.PXH
ZoneAlarmHoax.Win64.FakeRansom.a
GDataTrojan.Joke.PXH
AhnLab-V3Malware/Win64.Generic.C2476956
McAfeeArtemis!CC989B84CC4B
MalwarebytesHoax.FileCryptor
PandaTrj/CI.A
TrendMicro-HouseCallRansom_DOTZERO.THDBCAH
IkarusTrojan-Ransom.DotZero
FortinetRiskware/FakeRansom.A!tr
AVGWin64:Malware-gen
Qihoo-360Win32/Trojan.ae7

How to remove Hoax.FileCryptor?

Hoax.FileCryptor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment