Ransom

Ransom.JobCrypter removal guide

Malware Removal

The Ransom.JobCrypter is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.JobCrypter virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ransom.JobCrypter?


File Info:

crc32: B2016278
md5: 82dd311b67db9b4bfd80b0477d84f493
name: 82DD311B67DB9B4BFD80B0477D84F493.mlw
sha1: de87fbab7bb506fd95f11de12a124a70d68b5bd4
sha256: f5773e4517ef94e87022bae134a0298f6f9e688561c41e0ef5d4dd75d8defd51
sha512: 864f2f95703d7123983f65093b4f7bc0fc89a1a2c8cec55f4faadb906c0a084e460eb03ab2242cc56adec700611fc6ea21db7bd9dfcd0ad08eec784f7661f753
ssdeep: 6144:zCoOXzX+pIZnRrGknM3d0WDIEbXLpPLFzCtQG7g3M:WoOD+2Qkg04VLBCCG7g3M
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: boutique officielxa9 2020
Assembly Version: 3.9.0.0
InternalName: officiel.exe
FileVersion: 3.9.0.0
CompanyName: officiel
LegalTrademarks:
Comments: officiel
ProductName: officiel
ProductVersion: 3.9.0.0
FileDescription: officiel
OriginalFilename: officiel.exe

Ransom.JobCrypter also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.713333
FireEyeGeneric.mg.82dd311b67db9b4b
ALYacTrojan.Ransom.JobCrypter
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Variant.Razy.713333
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Trojan.HYSQ-3717
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.DOTHETUK.gen
AlibabaTrojan:Win32/DOTHETUK.49d0fb3d
NANO-AntivirusTrojan.Win32.DOTHETUK.hnbtap
AegisLabTrojan.MSIL.DOTHETUK.4!c
Ad-AwareGen:Variant.Razy.713333
EmsisoftGen:Variant.Razy.713333 (B)
ComodoMalware@#3cwv1ddakbg8f
F-SecureTrojan.TR/AD.JobCrypter.AA
DrWebTrojan.DownLoader33.60715
ZillyaTrojan.DOTHETUK.Win32.4508
TrendMicroTROJ_FRS.0NA103G820
McAfee-GW-EditionRansomware-GZV!82DD311B67DB
MaxSecureTrojan.Malware.73691240.susgen
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.JobCrypter.AA
MAXmalware (ai score=85)
Antiy-AVLTrojan/MSIL.DOTHETUK
MicrosoftTrojan:Win32/Ymacco.AAF5
ArcabitTrojan.Razy.DAE275
ZoneAlarmHEUR:Trojan.MSIL.DOTHETUK.gen
GDataGen:Variant.Razy.713333
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C4155589
McAfeeRansomware-GZV!82DD311B67DB
MalwarebytesRansom.JobCrypter
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.IOCEUVH
TrendMicro-HouseCallTROJ_FRS.0NA103G820
TencentMsil.Trojan.Dothetuk.Ebhd
IkarusTrojan.Agent
FortinetW32/DOTHETUK.IOCEUVH!tr.ransom
BitDefenderThetaGen:NN.ZemsilF.34670.zm0@aqyysCh
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.b7bb50
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.7ed

How to remove Ransom.JobCrypter?

Ransom.JobCrypter removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment