Ransom

Should I remove “Ransom.CryptoDevil.2”?

Malware Removal

The Ransom.CryptoDevil.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.CryptoDevil.2 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Ransom.CryptoDevil.2?


File Info:

crc32: 39967E4F
md5: c1893618c1639a0a93049d74d40164e1
name: C1893618C1639A0A93049D74D40164E1.mlw
sha1: be9898bbbaa3d1c484f71379ca57f5db0b4fac83
sha256: a428f4b0b19b80559eb5f2d4c1d5a8fd0aad7ff90e56b42e0bc7825181ea7efb
sha512: ea1d77a69ec742d8d727c4cccae79ff26776b4e912a81a551a70c6bfd8969d146245bc682de0e9d53fe484b5b7ba3756b585bd8b989fc7c21639ccca44ca9368
ssdeep: 3072:tHbjfeAfMdeTefCqItBbm/UeAfMdeTe9:5bjYeTeSbseTe9
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: Ramsomware.CryptoDevil.exe
FileVersion: 1.0.0.0
Comments: created by mutr0l
ProductName: Ramsomware.CryptoDevil
ProductVersion: 1.0.0.0
FileDescription: Ramsomware.CryptoDevil
OriginalFilename: Ramsomware.CryptoDevil.exe

Ransom.CryptoDevil.2 also known as:

K7AntiVirusTrojan ( 0050040f1 )
DrWebTrojan.Siggen7.15287
CAT-QuickHealTrojan.GenericFC.S12096475
ALYacTrojan.Ransom.CryptoDevil
CylanceUnsafe
ZillyaTrojan.FakeSupport.Win32.37
SangforTrojan.Win32.Malware.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Diztakun.72f24dc5
K7GWTrojan ( 0050040f1 )
Cybereasonmalicious.8c1639
SymantecInfostealer.Limitail
ESET-NOD32a variant of MSIL/FakeSupport.AS
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Diztakun.axbq
BitDefenderGen:Variant.Ransom.CryptoDevil.2
NANO-AntivirusTrojan.Win32.Diztakun.emnjfa
ViRobotTrojan.Win32.S.ScLock.780800
MicroWorld-eScanGen:Variant.Ransom.CryptoDevil.2
TencentMalware.Win32.Gencirc.11493a47
Ad-AwareGen:Variant.Ransom.CryptoDevil.2
SophosMal/Generic-R + Mal/CrypDevil-B
ComodoMalware@#31582fd8wrsu0
BitDefenderThetaGen:NN.ZemsilF.34692.Vq0@a8gSVcc
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPDEVIL.A
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Ransom.CryptoDevil.2
EmsisoftGen:Variant.Ransom.CryptoDevil.2 (B)
JiangminTrojan.Diztakun.cbi
WebrootW32.Trojan.Gen
AviraTR/FakeSupport.nioac
Antiy-AVLTrojan/Generic.ASMalwS.29B8677
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataGen:Variant.Ransom.CryptoDevil.2
McAfeeArtemis!C1893618C163
MAXmalware (ai score=100)
VBA32Trojan.Diztakun
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPDEVIL.A
RisingTrojan.FakeSupport!8.BA68 (TFE:C:KC4AjYblzfG)
YandexTrojan.Diztakun!xrJPEUTnD2s
IkarusTrojan.MSIL.Fakesupport
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.CryptoDevil.2?

Ransom.CryptoDevil.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment