Ransom

Ransom:MSIL/Nojocrypt.A removal guide

Malware Removal

The Ransom:MSIL/Nojocrypt.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/Nojocrypt.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

auth.smtp.1and1.fr

How to determine Ransom:MSIL/Nojocrypt.A?


File Info:

crc32: 325E252A
md5: f40466613bf4d1e1574ff104a7ae6278
name: F40466613BF4D1E1574FF104A7AE6278.mlw
sha1: be3440ebb4a94bb6000e80e68938d0b09837d77f
sha256: 019ed4e9ba8b441a869bd91b875ad26fbe08541f71a9aad8b42a272d85b894c2
sha512: f1c8abb238f18da13f508956c9a10c553a642f8da243f3560261f39df0aeafe6e042f4f660512e7f10a3c7bc1b4409f354cd5757a76c5ed1a5c2a0dd07e3f52b
ssdeep: 12288:kNK9qo0bqL1mO77hT1ldWix5X3KrEC7dr:J9qoWqLwOhRx5nKrEC79
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2000-2009 Heaventools Software
InternalName: PE Explorer
FileVersion: 1.99.6.1400
CompanyName: Heaventools Software
LegalTrademarks: PE Explorer is a trademark of Heaventools Software
Comments:
ProductName: PE Explorer
ProductVersion: 1.99.6.1400
FileDescription: PE Explorer
OriginalFilename: pexplorer.exe
Translation: 0x0000 0x04e3

Ransom:MSIL/Nojocrypt.A also known as:

K7AntiVirusTrojan ( 0053c6ff1 )
CynetMalicious (score: 99)
ALYacGen:Variant.Ransom.JobCrypter.14
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:MSIL/Filecoder.f2f6337a
K7GWTrojan ( 0053c6ff1 )
Cybereasonmalicious.13bf4d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.JobCrypter.C
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Ransom.Win32.Agent.gen
BitDefenderGen:Variant.Ransom.JobCrypter.14
MicroWorld-eScanGen:Variant.Ransom.JobCrypter.14
Ad-AwareGen:Variant.Ransom.JobCrypter.14
SophosML/PE-A + Troj/MSIL-LQX
ComodoMalware@#cd5srmh8d4nm
BitDefenderThetaGen:NN.ZemsilF.34738.Kq0@a8L8PCe
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.f40466613bf4d1e1
EmsisoftGen:Variant.Ransom.JobCrypter.14 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1133146
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.277DA92
MicrosoftRansom:MSIL/Nojocrypt.A
GDataGen:Variant.Ransom.JobCrypter.14
AhnLab-V3Malware/Win32.Generic.C317062
McAfeeArtemis!F40466613BF4
MAXmalware (ai score=100)
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
YandexTrojan.Filecoder!KIukRimc9eo
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder_JobCrypter.C!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ransom:MSIL/Nojocrypt.A?

Ransom:MSIL/Nojocrypt.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment