Ransom Trojan

Trojan-Ransom.Win32.CryptXXX.asdnuo removal instruction

Malware Removal

The Trojan-Ransom.Win32.CryptXXX.asdnuo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.CryptXXX.asdnuo virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.CryptXXX.asdnuo?


File Info:

crc32: 13089D2B
md5: b3243fdbee1f3f54e627c538108b1db8
name: B3243FDBEE1F3F54E627C538108B1DB8.mlw
sha1: 419f48a358fb86719eacede2758bcd91144c4314
sha256: 5260b6b44d7f7ca94073187b4cfe4c744481ce4421aafb4016e129fbc2a0eda3
sha512: 7fcad414d3fd35ea53fa1f0f274e625b897e9eef54c73c9056f7ffdffe053fd450e6145f09957d9f6fadc612727609f64f73e99c953cd026494d952e75629d01
ssdeep: 1536:iYno5LPP9G18UClkBWENb+F9T/G+wirFiqBzrBDDLXn6v8:iYo5wWUPB7+i4rBLXn6v8
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2003 - 2011 Nir Sofer
InternalName: NirCmd
FileVersion: 2.65
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.65
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.CryptXXX.asdnuo also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f8bc31 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CAT-QuickHealRansom.Crowti.MUE.A6
McAfeeRansomware-FTK!B3243FDBEE1F
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f8bc31 )
Cybereasonmalicious.bee1f3
CyrenW32/Ransom.CJ.gen!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.CryptXXX.asdnuo
BitDefenderGen:Variant.Barys.75140
NANO-AntivirusTrojan.Win32.Kryptik.evpqec
MicroWorld-eScanGen:Variant.Barys.75140
TencentMalware.Win32.Gencirc.10b65a9a
Ad-AwareGen:Variant.Barys.75140
SophosML/PE-A
ComodoMalware@#el7at53artho
BitDefenderThetaGen:NN.ZexaF.34686.gy0@aeiUtDdQ
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionRansomware-FTK!B3243FDBEE1F
FireEyeGeneric.mg.b3243fdbee1f3f54
EmsisoftGen:Variant.Barys.75140 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1110705
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Tovicrypt.A
GDataGen:Variant.Barys.75140
AhnLab-V3Malware/Win32.RL_Generic.R285865
Acronissuspicious
VBA32BScope.Trojan.Bagsu
MAXmalware (ai score=99)
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Kryptik!1.AB0F (CLOUD)
YandexTrojan.GenAsa!ao0N/xdCg2Q
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.CryptXXX.asdnuo?

Trojan-Ransom.Win32.CryptXXX.asdnuo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment