Ransom Trojan

Trojan-Ransom.Win32.CryptXXX.asdgst removal instruction

Malware Removal

The Trojan-Ransom.Win32.CryptXXX.asdgst is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.CryptXXX.asdgst virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.CryptXXX.asdgst?


File Info:

crc32: 3D0BDF85
md5: cfef500677041c8195019172beeb848d
name: CFEF500677041C8195019172BEEB848D.mlw
sha1: 333f8647023e5d25354b4cf95f28be7f8fa4328c
sha256: f5c824e2135eedc5eb16ccb4b9810ba7312217d8b98a79a783bbfc90b09a8306
sha512: 141c7a5c396fe2787e10d368b809a664f799ccee2a197f6233133f927ee2edcc424551689c956576852cea3226fd354845ca21b4a58ed8836dc569c7a1b19f81
ssdeep: 6144:yqPBYI1JW72GhKL0jEdCxi7knDAl1XS4oT:vOI1JW72Ghw5fg+1f
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013 Nero AG and its licensors
InternalName: Nero DiscMerge
FileVersion: 15,0,25,0
CompanyName: Nero AG
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Nero DiscMerge
SpecialBuild: 15,0,25,0
ProductVersion: 15,0,25,0
FileDescription: Nero DiscMerge Application
OriginalFilename: NeroDiscMerge.exe
Translation: 0x0409 0x04e4

Trojan-Ransom.Win32.CryptXXX.asdgst also known as:

K7AntiVirusTrojan ( 0051e0271 )
LionicTrojan.Win32.CryptXXX.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.22046
CAT-QuickHealDownldr.Freepds.MUE.ZZ5
McAfeeGenericRXDG-GU!CFEF50067704
CylanceUnsafe
ZillyaTrojan.CryptXXX.Win32.938
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/CryptXXX.62851d72
K7GWTrojan ( 0051e0271 )
Cybereasonmalicious.677041
CyrenW32/Tovicrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DPXE
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Goblinek [Inf]
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.CryptXXX.asdgst
BitDefenderGen:Variant.Zusy.320090
NANO-AntivirusTrojan.Win32.Encoder.evsvzn
MicroWorld-eScanGen:Variant.Zusy.320090
TencentMalware.Win32.Gencirc.10b58bb1
Ad-AwareGen:Variant.Zusy.320090
SophosML/PE-A + Mal/Swizzor-D
BitDefenderThetaGen:NN.ZexaF.34142.vy0@aycvNVti
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Crypmic-1
McAfee-GW-EditionGenericRXDG-GU!CFEF50067704
FireEyeGeneric.mg.cfef500677041c81
EmsisoftGen:Variant.Zusy.320090 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1144000
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22F84E1
MicrosoftRansom:Win32/Tovicrypt.A
ZoneAlarmTrojan-Ransom.Win32.CryptXXX.asdgst
GDataGen:Variant.Zusy.320090
AhnLab-V3Trojan/Win32.CryptXXX.R184966
Acronissuspicious
VBA32BScope.Trojan.Bagsu
MAXmalware (ai score=99)
MalwarebytesMalware.AI.182469934
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_Crypmic-1
RisingTrojan.Generic@ML.96 (RDML:p81upp54veYKY2smK6KHHQ)
YandexTrojan.GenAsa!/Jktgqz9N7U
IkarusTrojan-Ransom.Cryptprojectxxx
MaxSecureTrojan.Malware.74706075.susgen
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Goblinek [Inf]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.CryptXXX.asdgst?

Trojan-Ransom.Win32.CryptXXX.asdgst removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment