Home Malware Programs Trojans Trojan.Ransomcrypt.F

Trojan.Ransomcrypt.F

Posted: September 17, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 35
First Seen: September 17, 2013
Last Seen: February 13, 2023
OS(es) Affected: Windows

Trojan.Ransomcrypt.F is a Trojan that encrypts files on the infected computer and then urges the affected PC user to buy a password in order to decrypt them. When executed, Trojan.Ransomcrypt.F creates the potentially malicious file. Trojan.Ransomcrypt.F locks the desktop and the computer, encrypts files, and then demands a ransom to be paid via MoneyPak, Paysafecard, Ukash, cashU and Bitcoin by displaying a fake legal warning message. Trojan.Ransomcrypt.F may strive to contact the certain URLs.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\[GUID].exe File name: %AppData%\[GUID].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Additional Information

The following messages's were detected:
# Message
1The single copy of the private key, which will allow you to decrypt the files, located on a secret server on the Internet; the server will destroy the key after a time specified in this window. After that, nobody and never will be able to restore files. To obtain the private key for this computer, which will automatically decrypt files, you need to pay.

Loading...