Trojan

Trojan.Crypt.1 (B) removal guide

Malware Removal

The Trojan.Crypt.1 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.1 (B) virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Crypt.1 (B)?


File Info:

crc32: BCA83CC8
md5: dba2d13780641260f97021cad593a37f
name: DBA2D13780641260F97021CAD593A37F.mlw
sha1: 06af0b4109e7d13410244d30e7e4abe36877181d
sha256: ad51d941c61ec3ad40d89318ed209ff7bc9e8dd721fa4017844896ef65aa02d5
sha512: a7c01b2823a45c668339dace567f8f700f74927d03f16e85827e1a2c08786776cd47669caf60c283c4f028d7beb4fe27a5363fff15c5dfd83feef9e2bb03ee16
ssdeep: 196608:DTweEKUkTf3IPHvc+lj1egjUgjeOn3kBjw36LYnt8NaLwJ+If35Kt:DzUkkPHx0gyK36jw3HGaLwJ+Iv5Kt
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2013-2015
x6388x6743x65b9x5f0f: x514dx8d39x7248
FileVersion: 6.1.21.602
ProductVersion: 6.1.21.602
Translation: 0x0804 0x04b0

Trojan.Crypt.1 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 700000111 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.60234
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaPacked:Win32/MiscX.83c4f550
K7GWTrojan ( 700000111 )
Cybereasonmalicious.780641
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Autoit.Y suspicious
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Trojan.Crypt.1
NANO-AntivirusTrojan.Win32.Mlw.jchgse
MicroWorld-eScanGen:Variant.Trojan.Crypt.1
Ad-AwareGen:Variant.Trojan.Crypt.1
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Trojanaitinject.wc
FireEyeGeneric.mg.dba2d13780641260
EmsisoftGen:Variant.Trojan.Crypt.1 (B)
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASCommon.1B8
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Trojan.Crypt.1 (2x)
McAfeeArtemis!DBA2D1378064
MAXmalware (ai score=83)
MalwarebytesMalware.AI.4256476134
TrendMicro-HouseCallTROJ_GEN.R002H0CKJ21
RisingTrojan.MalCert!1.D834 (CLASSIC)
FortinetRiskware/Application
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Crypt.1 (B)?

Trojan.Crypt.1 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment