Trojan

Trojan.Crypt.63 (B) removal

Malware Removal

The Trojan.Crypt.63 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.63 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

hympsvtktvtm.biz
gecflsmlkiksr.info
lmobagwevuswt.com
yojadlsxgremt.net
mnyitvkvweugt.biz
apthwbgphbgvk.ru
nwssanxyjlucm.org
bynrdststigrm.co.uk
oxdatdlqkuwlt.info
caxywihkuribk.com
prwftrsoofadl.net
qfrrbwmnymewt.biz
qshmnhggpocml.ru
rgcyumafavggk.org
rcbwtytjcvcip.co.uk
spvjbenimdgcx.info
sdlenohbdferw.com
tqgqutbanmilv.net
alobefffkaduu.biz
nnjahnrsrqwol.ru
cpywpusdjvxal.org
prtvsdfqqmrtl.co.uk
cvssemgaxqfan.info
pxnrhusnfhyte.com
eadopctxwmafl.net
rcxnskgledtyl.biz
eqwfxqbbdksfj.ru
ferrfylwkloui.org
guhbjgoycgnka.co.uk
hicnqoyujhjai.info
gbbwxxcvqbukn.com
hovjfgmrxcqam.net
iflsjnptpwppl.biz
jsgfqvapwxlft.ru
atyeciagsxwf.org
nxajfnvlkgnl.co.uk
bywdvruhyqav.info
odxiywqmqyqc.com
ecektdpbellk.net
rgfpwilgvtcq.biz
fhcjnmkckeob.ru
sldoqrghcmfh.org
imhudssqdavu.co.uk
jcifxxmeunpf.info
jrftwcnrjsyl.com
khgerhhfbgsv.net
mumbunilonka.biz
nknlpscygbek.ru
nakaowdmugnq.org
oplkjcwamthb.co.uk
gibthrcvhtjr.info
tmcykaoxaiic.com
iqyprbwdlujm.net
vuauujjfejiw.biz
kqgaymrqshxw.ru
xuhfcueslvwh.org
myevjvmxwixr.co.uk
adfbmeyapwwc.info
objkicuurvql.com
pqkudkfckpcr.net
qjhgslpcvwqg.biz
ryiqntajoqcm.ru
sjoqawkpdjfq.org
typbufuwvdqw.co.uk
urmmkgfwhkfl.info
vhnwfopeaeqr.com
oxffaglvgpcl.net
ccgkdlhbxxsr.biz
pddetvykjtok.ru
dhejwbupbcfq.org
qakfxbdpvtfj.co.uk
eelkbgyuncvp.info
rfierqqeyxri.com
fjjjuvmjqgio.net
wqnvbqegqrbb.biz
xgogvvxtiful.ru
xvluugrutvna.org
ylmfplliljhk.co.uk
yssvylvagvey.info
aitgtqpnxjxj.com
axqusbjojaqx.net
bnrfngdcbnki.biz

How to determine Trojan.Crypt.63 (B)?


File Info:

crc32: 1E29C696
md5: f4699fbb6e88bc4bf42d8997ec8fe9fc
name: F4699FBB6E88BC4BF42D8997EC8FE9FC.mlw
sha1: 6b040e77ee4e4cdb1334f36893517af40690f8e6
sha256: bac94e2e424b347fc7719aaf2b09c8e60b42621fe3b2af644b822023d1067fc1
sha512: a27743f93ebb51321e59aa6604057f98f6a3a2343f3d6a5f85575ea6403a7e6bd0e1d3edddd29d0416c234b24dff5b7c0411c8c812ad6bb5198588ada41192c6
ssdeep: 12288:v1ZJ5j28ugtu6HQOLzMwjHFpclL80iztzTMXNbkG/iCvXeY:Lj1tfdReLbiNMXNbk/n
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) Skype Technologies S.A.
InternalName: SkypeIEPluginBroker-rel.exe
FileVersion: 6.3.0.11079
CompanyName: Skype Technologies S.A.
ProductName: Skype Click to Call
ProductVersion: 6.3.0.11079
FileDescription: Skype broker for IE add-on
OriginalFilename: SkypeIEPluginBroker.exe
Translation: 0x0409 0x04e4

Trojan.Crypt.63 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Generickd-62
McAfeeTrojan-FDYP!F4699FBB6E88
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.16601
SangforTrojan.Win32.GenericKD.frTH
CrowdStrikewin/malicious_confidence_80% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b6e88b
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.BQ
APEXMalicious
AvastWin32:Dropper-gen [Drp]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Trojan.Crypt.63
NANO-AntivirusTrojan.Win32.Blocker.cwcjza
MicroWorld-eScanGen:Variant.Trojan.Crypt.63
TencentWin32.Trojan.Filecoder.Ecab
Ad-AwareGen:Variant.Trojan.Crypt.63
SophosMal/Generic-S
ComodoMalware@#1a6o7427jzlt7
BitDefenderThetaGen:NN.ZexaF.34796.Yu0@aqktOtmi
VIPREWin32.Malware!Drop
TrendMicroTROJ_CRILOCK.RNW
McAfee-GW-EditionTrojan-FDYP!F4699FBB6E88
FireEyeGeneric.mg.f4699fbb6e88bc4b
EmsisoftGen:Variant.Trojan.Crypt.63 (B)
SentinelOneStatic AI – Malicious PE
WebrootCryptolocker.Gen
AviraTR/Crypt.XPACK.Gen8
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Crilock.B
GDataGen:Variant.Trojan.Crypt.63
AhnLab-V3Trojan/Win32.Zbot.R103307
Acronissuspicious
VBA32Hoax.Blocker
MAXmalware (ai score=89)
PandaGeneric Malware
TrendMicro-HouseCallTROJ_CRILOCK.RNW
RisingTrojan.Generic@ML.90 (RDML:43P81C9G4mnZwWE20oe/xg)
YandexTrojan.Blocker!JzEMIzOf3cE
IkarusTrojan-Spy.Zbot
FortinetW32/Kryptik.BXXO!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwkAezcA

How to remove Trojan.Crypt.63 (B)?

Trojan.Crypt.63 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment