Ransom

Ransom.Try2Cry (file analysis)

Malware Removal

The Ransom.Try2Cry is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Try2Cry virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

How to determine Ransom.Try2Cry?


File Info:

crc32: 10127EC8
md5: 8df542a559b6586c3d9c3b1ba06b4d1e
name: 8DF542A559B6586C3D9C3B1BA06B4D1E.mlw
sha1: ad1ffbfc161d33694646b278f38e81c09eb0844b
sha256: 590885b5afc3aa1d34720bb758fb2868bb0870557db2110e61397a5364c7f8b3
sha512: 25f4c08afd53ad9cb4cceb9d3f768d3f2ee5b0fc3868910c91d7ea7ee7b0c237ee18f5145db61419dd01d8da3179045aeb1e42a6fe93f6ac4926926da09141d1
ssdeep: 3072:FnGLBUggwIRLRw03Sbjl+vYtaO0ebLoD8tiInnq/FfrFdSe2y4lVu/C9Mq/A1Nh:gOggwIRLRwXPeYEnjomQmmPm6D0cU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft
Assembly Version: 1.0.7483.5350
InternalName: EncryptFile.exe
FileVersion: 1.0.7483.5350
CompanyName: Microsoft
LegalTrademarks: Microsoft
Comments: Microsoft
ProductName: Microsoft
ProductVersion: 1.0.7483.5350
FileDescription: Microsoft
OriginalFilename: EncryptFile.exe

Ransom.Try2Cry also known as:

K7AntiVirusTrojan ( 00569d7c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.32073
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Filecoder
MalwarebytesRansom.Try2Cry
ZillyaTrojan.Generic.Win32.1067269
SangforRansom.MSIL.Genasom.MSR
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:MSIL/Genasom.bc45a149
K7GWTrojan ( 00569d7c1 )
Cybereasonmalicious.559b65
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Filecoder.AAS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Agent-9377526-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.923880
NANO-AntivirusTrojan.Win32.Encoder.hmfkuf
ViRobotTrojan.Win32.S.Ransom.276480.B
SUPERAntiSpywareTrojan.Agent/Gen-MSFake[Less]
MicroWorld-eScanGen:Variant.Ursu.923880
TencentWin32.Trojan.Generic.Egev
Ad-AwareGen:Variant.Ursu.923880
SophosMal/Generic-R + Troj/Ransom-GAM
ComodoMalware@#2vhptazyz64v8
BitDefenderThetaGen:NN.ZemsilCO.34628.qm0@aqvVlBo
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.MSIL.TRYTOCRY.THGOABP
McAfee-GW-EditionGenericRXLK-WO!8DF542A559B6
FireEyeGeneric.mg.8df542a559b6586c
EmsisoftGen:Variant.Ursu.923880 (B)
JiangminTrojan.Generic.fpkve
WebrootW32.Trojan.Gen
AviraTR/Ransom.yzetr
eGambitUnsafe.AI_Score_92%
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ursu.923880
TACHYONRansom/W32.DN-Try2Cry.276480.B
AhnLab-V3Unwanted/Win32.Agent.C4155503
McAfeeGenericRXLK-WO!8DF542A559B6
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.MSIL.TRYTOCRY.THGOABP
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.Filecoder!R9LU0gjyi2A
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.AAS!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwMAsZsA

How to remove Ransom.Try2Cry?

Ransom.Try2Cry removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment