Ransom

Ransom.JaffCrypt.2 removal guide

Malware Removal

The Ransom.JaffCrypt.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.JaffCrypt.2 virus can do?

  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Anomalous binary characteristics

Related domains:

brookstecholiggronm.net

How to determine Ransom.JaffCrypt.2?


File Info:

crc32: 3DD25CEF
md5: 0a9184a6c34a37888a0098891dbd0ab3
name: 0A9184A6C34A37888A0098891DBD0AB3.mlw
sha1: 33ba65b7b5842ba8ab93eb1cfdd82a8799286954
sha256: 3de03e4fb59a1b401bdbfc16db1c9b001d66834beed2598b00bc4366aaa01758
sha512: 933ded21159480f61710dc09c794eb4929ff09d088b9e207e5fbf8ba7777d370d0e2170de761301eee37bdc3dd69cbc7e6580259d8149069f4a0ebbccad96505
ssdeep: 384:jD32Q/2RdQ3i0Fa3SbecpxCpNDGm4hEEZWasj8bs3YIZwsI67tkdn2fw5kSxodH:f32Qjav0cpMhFsYUYUwsf6NewJxyHzG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.JaffCrypt.2 also known as:

LionicTrojan.Win32.Jaff.tqP5
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.29734
ALYacGen:Variant.Ransom.JaffCrypt.2
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Filecoder.Win32.10461
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0050e6c21 )
K7AntiVirusTrojan ( 0050e6c21 )
SymantecRansom.Jaff
ESET-NOD32a variant of Win32/Filecoder.Jaff.B
APEXMalicious
AvastWin32:Filecoder-AX [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Jaff.cc
BitDefenderGen:Variant.Ransom.JaffCrypt.2
NANO-AntivirusTrojan.Win32.Jaff.gcadow
MicroWorld-eScanGen:Variant.Ransom.JaffCrypt.2
TencentWin32.Trojan.Jaff.Hfd
Ad-AwareGen:Variant.Ransom.JaffCrypt.2
SophosMal/Generic-S
ComodoMalware@#1xxu6vjcsojdu
BitDefenderThetaAI:Packer.1F17378B1F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nh
FireEyeGeneric.mg.0a9184a6c34a3788
EmsisoftGen:Variant.Ransom.JaffCrypt.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Jaff.p
WebrootW32.Jaff.cc
AviraHEUR/AGEN.1115164
Antiy-AVLTrojan/Generic.ASMalwS.2C73F35
MicrosoftRansom:Win32/Jaffrans.A!rsm
ZoneAlarmTrojan-Ransom.Win32.Jaff.cc
GDataGen:Variant.Ransom.JaffCrypt.2
AhnLab-V3Malware/Win32.Generic.C2005675
McAfeeArtemis!0A9184A6C34A
MAXmalware (ai score=81)
VBA32BScope.TrojanRansom.Jaff
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.93 (RDML:ocxNfcaOM/qtkTXUxkobWA)
YandexTrojan.GenAsa!i/MH/E4wrmQ
IkarusTrojan-Ransom.Jaff
FortinetW32/Jaff.B!tr.ransom
AVGWin32:Filecoder-AX [Trj]
Paloaltogeneric.ml

How to remove Ransom.JaffCrypt.2?

Ransom.JaffCrypt.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment