Ransom

How to remove “Ransom.CryptXXX.1 (B)”?

Malware Removal

The Ransom.CryptXXX.1 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.CryptXXX.1 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Romanian
  • Anomalous binary characteristics

How to determine Ransom.CryptXXX.1 (B)?


File Info:

crc32: F874A5CC
md5: b33680468aad8228312808c800b6ef47
name: B33680468AAD8228312808C800B6EF47.mlw
sha1: bea4addb6c07a6f20cc20b19b5e1925467f2fda1
sha256: b57b52ce48def9f6a862c71449fc6e32b6ae151a11903aaec37a2b059c38bc65
sha512: a094bfee00118e52f1ba8f5537998194016097a0be98e01ce01137b230062c9adf1d30d2c3a7dc5b4b90d9a92912248b835a60b71ffa17103f7b3f5da8e14475
ssdeep: 1536:oDdnqrA3VAkZyuCDqpEMrow5NCrWVp1EO0xlfxyq7b28qDLD:Sd8AlAknCD7u5UrkNqHy6ILD
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: c m d
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b1

Ransom.CryptXXX.1 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004fc7c71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CynetMalicious (score: 100)
CAT-QuickHealDownldr.Freepds.MUE.ZZ5
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004fc7c71 )
Cybereasonmalicious.68aad8
CyrenW32/S-b5a1ff1e!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HGEN
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Kryptik.evpucr
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentMalware.Win32.Gencirc.10b58cdb
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34628.fy0@ay47NIhO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionGenericRXDG-IX!B33680468AAD
FireEyeGeneric.mg.b33680468aad8228
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Tovicrypt.A
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.Ransomlock.R214507
Acronissuspicious
McAfeeGenericRXDG-IX!B33680468AAD
MAXmalware (ai score=99)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.929094131
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingRansom.CryptXXX!8.5DF0 (CLOUD)
YandexTrojan.GenAsa!2ZDA28gA8co
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.ece

How to remove Ransom.CryptXXX.1 (B)?

Ransom.CryptXXX.1 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment