Ransom

What is “Ransom:Win32/Pocrimcrypt!rfn”?

Malware Removal

The Ransom:Win32/Pocrimcrypt!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Pocrimcrypt!rfn virus can do?

  • Reads data out of its own binary image
  • Attempts to modify desktop wallpaper
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Pocrimcrypt!rfn?


File Info:

crc32: 26821423
md5: 6ceb89615fe636e28cdaa6f2989162a7
name: 6CEB89615FE636E28CDAA6F2989162A7.mlw
sha1: 7b9c9b94ee4b7d90daed30d30eb2f586a9bef470
sha256: aa21cd3aae7bf488655c16c7d8b860b8524ce9a5d1c6e746fcd2baba007d97fe
sha512: 5ac04130b8f231995556cd6a4159660210d1926ff43637b91d6eafb5059004bde46ab81c80e61830189c03503002149b266c8a5d664694ddd300d0120cd5e52a
ssdeep: 12288:ohkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcE4aJPU:QRmJkcoQricOIQxiZY1ia5U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Ransom:Win32/Pocrimcrypt!rfn also known as:

K7AntiVirusTrojan ( 00523ae81 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24597
ALYacGen:Variant.Strictor.150341
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.11221
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/CRYPTEIGHT.9af5a899
K7GWTrojan ( 00523ae81 )
Cybereasonmalicious.15fe63
ESET-NOD32a variant of Win32/Filecoder.Crypt888.C
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Ransom.Win32.Mircop.gen
BitDefenderGen:Variant.Strictor.150341
NANO-AntivirusTrojan.Win32.Encoder.gmtupj
SUPERAntiSpywareRansom.Crypt888/Variant
MicroWorld-eScanGen:Variant.Strictor.150341
TencentWin32.Trojan.Filecoder.Wtod
Ad-AwareGen:Variant.Strictor.150341
SophosMal/Generic-S
ComodoMalware@#77s36aqhkgqo
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.AutoIt.CRYPTEIGHT.SMTH
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
FireEyeGen:Variant.Strictor.150341
EmsisoftGen:Variant.Strictor.150341 (B)
JiangminTrojan.Yakes.ypi
AviraHEUR/AGEN.1110296
MicrosoftRansom:Win32/Pocrimcrypt!rfn
GDataGen:Variant.Strictor.150341
AhnLab-V3Trojan/Win32.FileCoder.R263500
McAfeeArtemis!6CEB89615FE6
MAXmalware (ai score=83)
MalwarebytesRansom.Microcop
PandaTrj/CI.A
TrendMicro-HouseCallRansom.AutoIt.CRYPTEIGHT.SMTH
RisingTrojan.Crypt888!1.AFB9 (CLASSIC)
IkarusTrojan-Ransom.Crypt888
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Crypt888.C!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Pocrimcrypt!rfn?

Ransom:Win32/Pocrimcrypt!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment