Hoax.FileCryptor

What is Hoax.FileCryptor infection?

In this short article you will find about the meaning of Hoax.FileCryptor and also its unfavorable impact on your computer system. Such ransomware are a type of malware that is elaborated by on-line frauds to require paying the ransom by a sufferer.

In the majority of the cases, Hoax.FileCryptor ransomware will advise its victims to initiate funds transfer for the objective of counteracting the modifications that the Trojan infection has actually introduced to the victim’s device.

Hoax.FileCryptor Summary

These modifications can be as adheres to:

  • Anomalous binary characteristics;
  • Unusual version info supplied for binary;
  • Ciphering the records located on the victim’s hard drive — so the victim can no longer utilize the data;
  • Preventing normal access to the target’s workstation;

Hoax.FileCryptor

The most typical channels where Hoax.FileCryptor are injected are:

  • By ways of phishing emails;
  • As an effect of customer winding up on a resource that holds a malicious software;

As quickly as the Trojan is successfully infused, it will either cipher the information on the victim’s computer or avoid the gadget from functioning in an appropriate manner – while also positioning a ransom note that discusses the need for the sufferers to impact the settlement for the purpose of decrypting the documents or bring back the data system back to the preliminary condition. In most instances, the ransom note will certainly show up when the customer restarts the PC after the system has already been damaged.

Hoax.FileCryptor distribution networks.

In various edges of the world, Hoax.FileCryptor grows by leaps and bounds. However, the ransom notes and tricks of obtaining the ransom money quantity may vary depending on certain local (regional) setups. The ransom notes and tricks of extorting the ransom amount might differ depending on specific regional (local) setups.

Ransomware injection

As an example:

    Faulty informs concerning unlicensed software application.

    In particular areas, the Trojans typically wrongfully report having actually spotted some unlicensed applications made it possible for on the victim’s gadget. The sharp then requires the individual to pay the ransom.

    Faulty declarations concerning prohibited material.

    In nations where software program piracy is much less preferred, this technique is not as efficient for the cyber fraudulences. Additionally, the Hoax.FileCryptor popup alert may incorrectly assert to be originating from a law enforcement organization and will report having located child pornography or various other illegal data on the gadget.

    Hoax.FileCryptor popup alert may falsely claim to be deriving from a regulation enforcement establishment and also will report having located kid pornography or other unlawful data on the gadget. The alert will in a similar way consist of a need for the customer to pay the ransom.

Technical details

File Info:

crc32: F043CBE1md5: cc989b84cc4b5688931e20cc4a515887name: CC989B84CC4B5688931E20CC4A515887.mlwsha1: 25fe7ffe900f84bc67bb90b9ada4040a35df05f2sha256: 946f2c19bdf5edd48bedf507d44466da678a7b2a44cf848e4c35d92a2738f16esha512: 9c2b895cd96262ec86824cec222b2fc1d4e74fc1104917c7207cbef6aceb6c5cef24d2762d6df1966f508eca3efa140183f96f02be4bdcf209abf58fafb997cdssdeep: 1536:8Qb2uO2dn34rhdPVr4BADbWJr+UFDbtxTn8PVYGX:SwZ4vif9Dbtxb8PVvXtype: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0LegalCopyright: Copyright xa9 Microsoft 2018Assembly Version: 1.2.13.5InternalName: RansomDotZeroCMD.exeFileVersion: 1.2.13.5CompanyName: Rekt-Cheats.ML DigitalGroup LLCLegalTrademarks: Comments: RaaS RansomWareProductName: Ransom DotZero CMD.RansomProductVersion: 1.2.13.5FileDescription: Ransom DotZero CMD RansomOriginalFilename: RansomDotZeroCMD.exe

Hoax.FileCryptor also known as:

GridinSoft Trojan.Ransom.Gen
K7AntiVirus Riskware ( 0040eff71 )
Lionic Hacktool.Win64.FakeRansom.3!c
DrWeb Joke.Runsom.1
ALYac Trojan.Ransom.DotZeroCMD
Cylance Unsafe
Zillya Tool.PXH.Win64.1
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba RiskWare:Win64/FakeRansom.06a7399e
K7GW Riskware ( 0040eff71 )
Cybereason malicious.4cc4b5
Symantec Trojan.Gen.MBT
Avast Win64:Malware-gen
Kaspersky Hoax.Win64.FakeRansom.a
BitDefender Trojan.Joke.PXH
MicroWorld-eScan Trojan.Joke.PXH
Tencent Win64.Trojan-psw.Fakeransom.Tbim
Ad-Aware Trojan.Joke.PXH
Sophos Mal/Generic-R + Troj/DotZero-A
Comodo Malware@#2m8rnmp3nvcc4
VIPRE Trojan.Win32.Generic!BT
TrendMicro Ransom_DOTZERO.THDBCAH
McAfee-GW-Edition Artemis!Trojan
FireEye Trojan.Joke.PXH
Emsisoft Trojan.Joke.PXH (B)
Webroot W32.Trojan.Joke
Avira JOKE/Redcap.mrsrx
Microsoft Trojan:Win32/Occamy.B
Arcabit Trojan.Joke.PXH
ZoneAlarm Hoax.Win64.FakeRansom.a
GData Trojan.Joke.PXH
AhnLab-V3 Malware/Win64.Generic.C2476956
McAfee Artemis!CC989B84CC4B
Malwarebytes Hoax.FileCryptor
Panda Trj/CI.A
TrendMicro-HouseCall Ransom_DOTZERO.THDBCAH
Ikarus Trojan-Ransom.DotZero
Fortinet Riskware/FakeRansom.A!tr
AVG Win64:Malware-gen
Qihoo-360 Win32/Trojan.ae7

How to remove Hoax.FileCryptor virus?

Unwanted application has ofter come with other viruses and spyware. This threats can steal account credentials, or crypt your documents for ransom.
Reasons why I would recommend GridinSoft1

Run the setup file.

Run Setup.exe
GridinSoft Anti-Malware Setup

Press “Install” button.

GridinSoft Anti-Malware Install

Once installed, Anti-Malware will automatically run.

GridinSoft Anti-Malware Splash-Screen

Wait for the Anti-Malware scan to complete.

GridinSoft Anti-Malware Scanning

Click on “Clean Now”.

GridinSoft Anti-Malware Scan Result

Are Your Protected?

Full version of GridinSoft

If the guide doesn’t help you to remove Hoax.FileCryptor you can always ask me in the comments for getting help.

References

    About the author

    Robert Bailey

    Security engineer focused on malware behavior, removal workflows, and Windows hardening. Robert reviews threat articles for practical accuracy, checking detection names, symptoms, and cleanup steps before publication.

    Leave a Comment