Ransom

About “Ransom.Crowti.G4” infection

Malware Removal

The Ransom.Crowti.G4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Crowti.G4 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Crowti.G4?


File Info:

crc32: DDD95B84
md5: 44d0b812c69c60a3c32e66a87b8bab29
name: 44D0B812C69C60A3C32E66A87B8BAB29.mlw
sha1: 32d583d44da45093017ea3f2dc0b36374d5342b5
sha256: a36a7d642bd93b2f7704e6187f6a14f3e1bee8e19584e3fc669686055207ca95
sha512: 3e6cc65c89119af7e1310a757092856d6d1b0574cf52a24c61d703fcf78a279dc3d3f11d48cb4975e028ea913769e84ac3a3c0a55e80521335db982f795726dc
ssdeep: 3072:ZkN1KmldMIXSbxA/n2YF/qyA1qnTKnf6UhAJCoE5jsiGn54:ZkeedMIXS6+Yopnf2JClj6n5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2011 Igor Pavlov
InternalName: 7zg
FileDescription: 7-Zip GUI
FileVersion: 9.23 alpha
CompanyName: Ig or Pavlov
Translation: 0x0409 0x04b0

Ransom.Crowti.G4 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4395
CynetMalicious (score: 100)
CAT-QuickHealRansom.Crowti.G4
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.7549
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Cerber.35bb0c44
K7GWTrojan ( 005224381 )
Cybereasonmalicious.2c69c6
BaiduWin32.Trojan.FileCoder.a
CyrenW32/Cerber.PJWK-0605
SymantecRansom.Cerber
ESET-NOD32Win32/Filecoder.Cerber.B
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Tinba-9844531-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Encoder.eeapcy
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentMalware.Win32.Gencirc.10b63cdd
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Tinba-T
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaGen:NN.ZexaF.34670.pq0@auBDG2gi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.CBQ1654
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.44d0b812c69c60a3
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfdel.bsh
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1140560
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.SelfDel.ca.(kcloud)
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Ransom.Cerber.1
AegisLabTrojan.Win32.SelfDel.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Trojan/Win32.Cerber.R180437
Acronissuspicious
McAfeeRansomware-GCQ!44D0B812C69C
MAXmalware (ai score=100)
VBA32BScope.Trojan.Menti
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CERBER.CBQ1654
RisingRansom.FileCryptor!8.1A7 (KTSE)
YandexTrojan.SelfDel!Sv1iL7TpBlo
IkarusTrojan.Win32.Filecoder
FortinetW32/Qbot.CQ!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQB65YA

How to remove Ransom.Crowti.G4?

Ransom.Crowti.G4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment