Ransom

About “Ransom:Win32/Cryptomix.A” infection

Malware Removal

The Ransom:Win32/Cryptomix.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Cryptomix.A virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Cryptomix.A?


File Info:

crc32: 16059BE2
md5: 1b5c00761984171f0536ac2bb0643529
name: 1B5C00761984171F0536AC2BB0643529.mlw
sha1: d1b77828c33658bb514b3a0dcb768d38a2fb8e48
sha256: 4fdf1ccefb4a3447fbca6df7bf1dbe854d3e474cad13bebf336540b8962b2f12
sha512: bb80936bc0e129de1c1e1f8d2e947ae2a105dfe2c7eb124a398fafd0db2bebba0d2c914ad5b5bb1f344b2ec69137955f941f3b38dd63df796296d6f0d34e2873
ssdeep: 1536:VikgXlop3DS+RUzMufHKoJUfv9l5naANE:Vi+yfHKoJk9VNE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Cryptomix.A also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.Mole.8FA9DDF5
FireEyeGeneric.mg.1b5c00761984171f
ALYacTrojan.Ransom.Mole
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7612
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051123e1 )
BitDefenderGeneric.Ransom.Mole.8FA9DDF5
K7GWTrojan ( 0051123e1 )
Cybereasonmalicious.619841
SymantecW32.Tapin
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cryptomix.f2c65fc3
NANO-AntivirusTrojan.Win32.Filecoder.eqqxkq
ViRobotTrojan.Win32.Ransom.77672
RisingRansom.Cryptomix!8.ECD2 (CLOUD)
Ad-AwareGeneric.Ransom.Mole.8FA9DDF5
SophosMal/Generic-S + Troj/Hydran-A
ComodoMalware@#tokv48wl12zf
F-SecureHeuristic.HEUR/AGEN.1123427
DrWebTrojan.Encoder.11008
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPAURA.SHLDL
McAfee-GW-EditionGenericRXCG-WR!1B5C00761984
EmsisoftTrojan-Ransom.HydraCrypt (A)
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Generic.bcimt
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1123427
eGambitUnsafe.AI_Score_83%
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Cryptomix.A
ArcabitGeneric.Ransom.Mole.8FA9DDF5
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.Mole.B
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Ransom_.R294701
Acronissuspicious
McAfeeGenericRXCG-WR!1B5C00761984
MAXmalware (ai score=95)
VBA32BScope.Trojan.Encoder
MalwarebytesGeneric.Malware/Suspicious
PandaAdware/SecurityProtection
ESET-NOD32a variant of Win32/Filecoder.HydraCrypt.J
TrendMicro-HouseCallRansom_CRYPAURA.SHLDL
TencentWin32.Trojan.Raas.Auto
YandexTrojan.Agent!LJo/hio7dx0
SentinelOneStatic AI – Malicious PE
FortinetW32/FileCoder.HYDRACRYPT.L!tr
BitDefenderThetaGen:NN.ZexaF.34590.euZ@ayq0Jlh
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Cryptomix.HxQBGmcA

How to remove Ransom:Win32/Cryptomix.A?

Ransom:Win32/Cryptomix.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment