Ransom

Ransom:Win32/Crysis.PA!rfn removal instruction

Malware Removal

The Ransom:Win32/Crysis.PA!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Crysis.PA!rfn virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/Crysis.PA!rfn?


File Info:

crc32: 94EF3506
md5: 43c6959a2a8f737cc2e2f28e2228c540
name: 43C6959A2A8F737CC2E2F28E2228C540.mlw
sha1: f49b270d7d31d247b1d00fa6f200278e8f5fe3cb
sha256: 4f6e452d4d4c4c536b537d982d8f70793c80444e7692a592c951fe399b5d2478
sha512: 18be057f5be80d4e9ecd2e3062e2d9140cfa7582bb350e0e534b981863217140cd03c2d1dc9a8fcc1d7f8e3943a627f6f3b70e26c5df4810b8669bfc0ba1fcbc
ssdeep: 3072:NU3Z5iGYegVNiJgXkMUeLxeNi7fB285BV99eCkZacy/p9ZMG2+kcdjE:K3Z5iXegTk2ceB2jTZTqsLi
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/Crysis.PA!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00548c911 )
LionicTrojan.Win32.Dofoil.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Mint.Zamg.8.FD872370
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Crypmod.81697961
K7GWTrojan ( 00548c911 )
Cybereasonmalicious.a2a8f7
SymantecInfostealer.Rultazo
ESET-NOD32a variant of Win32/Kryptik.GQIK
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Mint.Zamg.8.FD872370
NANO-AntivirusTrojan.Win32.Dofoil.fnqcge
MicroWorld-eScanDeepScan:Generic.Mint.Zamg.8.FD872370
TencentWin32.Trojan.Generic.Pdmk
Ad-AwareDeepScan:Generic.Mint.Zamg.8.FD872370
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.Ransom.GandCrab.PW@86k2f3
F-SecureHeuristic.HEUR/AGEN.1107509
BitDefenderThetaGen:NN.ZexaF.34796.jmGfaq5UG0dG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.43c6959a2a8f737c
EmsisoftDeepScan:Generic.Mint.Zamg.8.FD872370 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Crypmod.mv
AviraHEUR/AGEN.1107509
Antiy-AVLTrojan/Generic.ASMalwS.2AB4C8A
MicrosoftRansom:Win32/Crysis.PA!rfn
ArcabitDeepScan:Generic.Mint.Zamg.8.FD872370
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Mint.Zamg.8.FD872370
AhnLab-V3Trojan/Win32.Gandcrab.C3055469
Acronissuspicious
McAfeeArtemis!43C6959A2A8F
MAXmalware (ai score=82)
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B5F0 (CLASSIC)
YandexTrojan.DL.Dofoil!RFB71JMkk10
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.74161587.susgen
FortinetW32/Kryptik.GQHV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Crypmod.HwsBEpsA

How to remove Ransom:Win32/Crysis.PA!rfn?

Ransom:Win32/Crysis.PA!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment