Spy

Spyware.Crypt removal instruction

Malware Removal

The Spyware.Crypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Crypt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Spyware.Crypt?


File Info:

name: 10246A73997B8EA83BD7.mlw
path: /opt/CAPEv2/storage/binaries/7af43544ce6587c3d553cbe9a1ec8ab629d6fc87f2a40b63cc4b92770085d617
crc32: D705CEE5
md5: 10246a73997b8ea83bd7e791806b9c91
sha1: fdef259b38005663926b6b8553f2d35324f63099
sha256: 7af43544ce6587c3d553cbe9a1ec8ab629d6fc87f2a40b63cc4b92770085d617
sha512: 33e9f58219b2d0f61676c935d83f71e6239eb8f0012cf4b8fada1ff59576fc27b608f9e534bae283b546dbad269ad08a808b12034ac90575245df978311e6c25
ssdeep: 3072:l/+PcU7SwIlcwE5PQcZ6qGtKY1r63fx8h0A2aH/Z2Lx6:ASwKOPQVqGr1Qf6GQhT
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1424439B77792DB77D5D1D17B9B2351A9C520A9F0F2DC24CEE1402B1E6A201E68FF0126
sha3_384: 66fddb1f43667eb59c6e17c93ae05281664c687dda36a9177af27fed48f58ed1313f95bedcf829ea3ab3d67ffe5cfb92
ep_bytes: e807300000e9a4feffff3b0d04b14300
timestamp: 2023-06-14 17:21:26

Version Info:

Comments: Esta es una aplicación legítima.
CompanyName: Santander
FileDescription: Santander Produit
FileVersion: 186
InternalName: AplicacionInterna
LegalCopyright: Derechos de autor © Santander Todos los derechos reservados.
LegalTrademarks: Marcas registradas © Santander
OriginalFilename: app.exe
ProductName: Aplicacion
ProductVersion: 186
Translation: 0x0407 0x04b0

Spyware.Crypt also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lvqc
DrWebTrojan.PWS.RedLineNET.7
MicroWorld-eScanTrojan.GenericKD.67524889
FireEyeGeneric.mg.10246a73997b8ea8
MalwarebytesSpyware.Crypt
VIPREGen:Variant.Ser.Mikey.2543
SangforTrojan.Win32.Agent.V25k
K7GWTrojan ( 005a6ef41 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ser.Mikey.D9EF
BitDefenderThetaGen:NN.ZexaF.36250.pq2@aeNj2!fi
VirITTrojan.Win32.GenusT.DNBE
CyrenW32/Kryptik.JZU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTUE
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.67524889
AvastWin32:PWSX-gen [Trj]
RisingBackdoor.Convagent!8.123DC (TFE:5:ZRMSRuzQdbJ)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.RedLineSteal.hcgfy
TrendMicroTrojanSpy.Win32.REDLINE.YXDFOZ
McAfee-GW-EditionBehavesLike.Win32.Suspect.dh
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.67524889 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/AD.RedLineSteal.hcgfy
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataWin32.Trojan.Agent.R8NNTG
GoogleDetected
AhnLab-V3Trojan/Win.CrypterX-gen.R586745
McAfeeArtemis!10246A73997B
VBA32BScope.TrojanPSW.RedLine
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDFOZ
IkarusAdWare.Lollipop
FortinetW32/Kryptik.HTUE!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Spyware.Crypt?

Spyware.Crypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment