Ransom

Ransom.NoobCrypt.1 removal tips

Malware Removal

The Ransom.NoobCrypt.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.NoobCrypt.1 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup

How to determine Ransom.NoobCrypt.1?


File Info:

crc32: B5F82A76
md5: 3bc2d2cf32c1e3a80bbdc5bc90c09d84
name: 3BC2D2CF32C1E3A80BBDC5BC90C09D84.mlw
sha1: 65d640224fa0d5ed5f8841036ffb40916e5627ec
sha256: 7b918b0b10c896112cc8f1eeed3be801df0f540a6933846a55a302ed05b5130c
sha512: d9ff3556a801c39f2e29fcfa68dbce651d120ebb2efdc32f0645e9a6ff1e5580fff47aa2b703bceb7013327a3f41d343faf097def02e727706028f015e4b118e
ssdeep: 768:wVFF68TvpyqtYuPgUM5SBaUh4SRyMusP2+gTlBFu9PlrjzI/1U3ZI/:wVFJptPPMQPhXIPllBFu99PzI/1Uo
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: WindowsApplication4.exe
FileVersion: 1.0.0.0
ProductName: WindowsApplication4
ProductVersion: 1.0.0.0
FileDescription: WindowsApplication4
OriginalFilename: WindowsApplication4.exe

Ransom.NoobCrypt.1 also known as:

K7AntiVirusTrojan ( 004b89791 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader23.45375
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.NoobCrypt.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004b89791 )
Cybereasonmalicious.f32c1e
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.MSIL.SpyGate.abic
BitDefenderGen:Variant.Ransom.NoobCrypt.1
NANO-AntivirusTrojan.Win32.SpyGate.fbfcdv
MicroWorld-eScanGen:Variant.Ransom.NoobCrypt.1
TencentMsil.Backdoor.Spygate.Lnok
Ad-AwareGen:Variant.Ransom.NoobCrypt.1
SophosGeneric PUA GF (PUA)
ComodoMalware@#7q6mlj7e3cku
BitDefenderThetaGen:NN.ZemsilF.34608.dm0@aixe8sh
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.3bc2d2cf32c1e3a8
EmsisoftGen:Variant.Ransom.NoobCrypt.1 (B)
SentinelOneStatic AI – Malicious PE
AviraBDS/SpyGate.zxtvx
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ransom.NoobCrypt.1
AegisLabTrojan.MSIL.SpyGate.m!c
GDataGen:Variant.Ransom.NoobCrypt.1
AhnLab-V3Trojan/Win32.RL_Bladabindi.R265530
McAfeeArtemis!3BC2D2CF32C1
MAXmalware (ai score=99)
MalwarebytesMachineLearning/Anomalous.97%
PandaTrj/GdSda.A
RisingBackdoor.SpyGate!8.E154 (CLOUD)
YandexBackdoor.SpyGate!we56Cn1shDg
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/SpyGate.ABIC!tr.bdr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.SpyGate.HwMAEpsA

How to remove Ransom.NoobCrypt.1?

Ransom.NoobCrypt.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment