Ransom Trojan

Trojan.Ransom.Crypt888 removal

Malware Removal

The Trojan.Ransom.Crypt888 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Crypt888 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Ransom.Crypt888?


File Info:

name: F6C05CD3C374DFA7580C.mlw
path: /opt/CAPEv2/storage/binaries/7e94a07bf9c5034769a3e201a9329b991346a8c12abf88683a5fa332c148eacd
crc32: AA80CD5B
md5: f6c05cd3c374dfa7580cf2d473da0772
sha1: b839d28f897cb57957b9ca9c301e45ae6ac943a7
sha256: 7e94a07bf9c5034769a3e201a9329b991346a8c12abf88683a5fa332c148eacd
sha512: 363295024c505238871094d7d92d70721aacb82ed8116fc7490f13de76b41481dd79d6fbaf93b782bd4ed270544279ef0e614b44c91cc92542c4780b95d5ddce
ssdeep: 12288:ghkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcE4a735lIP5J1:oRmJkcoQricOIQxiZY1iaD5MJ1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17805B022F5C68036C2B323B19E7EF76A963D69360337D19727C82D316EA05416B39763
sha3_384: 5726ffb3e30f9afa08b4d12361e4fd6e2bac6fba5188dd6936fd250d79c2ef49cfd0aa567642f9a5cc530f2a23f6df7a
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Trojan.Ransom.Crypt888 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Autoit.lzM7
MicroWorld-eScanGen:Variant.Ransom.Locked.2
ClamAVWin.Malware.Autoit-6992337-0
FireEyeGeneric.mg.f6c05cd3c374dfa7
McAfeeDropper-AutoIt.o
MalwarebytesRansom.Microcop
VIPREGen:Variant.Ransom.Locked.2
SangforRansom.Win32.Filecoder.Vp1r
K7AntiVirusTrojan ( 0055e3ef1 )
AlibabaRansom:Win32/Pocrimcrypt.b6daec79
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.3c374d
CyrenW32/Autoit.XNSP-2917
SymantecRansom.Cryptolocker
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Crypt888.B
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyUDS:Trojan-Ransom.Win32.Encoder
BitDefenderGen:Variant.Ransom.Locked.2
AvastAutoIt:Ransom-L [Trj]
RisingRansom.Crypt888/Autoit!1.C27B (CLASSIC)
Ad-AwareGen:Variant.Ransom.Locked.2
EmsisoftGen:Variant.Ransom.Locked.2 (B)
DrWebTrojan.Encoder.24597
TrendMicroRansom.AutoIt.CRYPTEIGHT.SMTH
McAfee-GW-EditionBehavesLike.Win32.Ransomware.bh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GDataGen:Variant.Ransom.Locked.2
JiangminTrojan.Encoder.d
AviraHEUR/AGEN.1229391
Antiy-AVLTrojan/Generic.ASBOL.C6D6
ArcabitTrojan.Ransom.Locked.2
MicrosoftRansom:Win32/Pocrimcrypt.A
GoogleDetected
AhnLab-V3Trojan/Win32.FileCoder.R291305
BitDefenderThetaAI:Packer.E19D7A3317
ALYacTrojan.Ransom.Crypt888
MAXmalware (ai score=88)
CylanceUnsafe
TrendMicro-HouseCallRansom.AutoIt.CRYPTEIGHT.SMTH
TencentWin32.Trojan.Filecoder.Bujl
IkarusTrojan-Ransom.Crypt888
MaxSecureTrojan.Autoit.AZA
FortinetW32/Filecoder.DYB!tr
AVGAutoIt:Ransom-L [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Ransom.Crypt888?

Trojan.Ransom.Crypt888 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment