Ransom

What is “Ransom.AVCrypt.17”?

Malware Removal

The Ransom.AVCrypt.17 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.AVCrypt.17 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Operates on local firewall’s policies and settings
  • Deletes executed files from disk

How to determine Ransom.AVCrypt.17?


File Info:

name: 257B500A2E9C018A1CB8.mlw
path: /opt/CAPEv2/storage/binaries/04863bf8045b13f6c249384c65f55ab614c4d39f0506676305135c417915e941
crc32: FB61D023
md5: 257b500a2e9c018a1cb89858c0ab46ef
sha1: e597b23cd7a028eb00601593c47d9dc2a42ec08c
sha256: 04863bf8045b13f6c249384c65f55ab614c4d39f0506676305135c417915e941
sha512: c01bdb9d47db1bedcc36e13a8b10b68fb0aeb2ebf14ab2887765f9f05a6e8fac097d639fecab8431388e0124bcdb37963409f0b6d82868e7eb60c00a7bdaecc8
ssdeep: 768:BfSqcTRhm1cp07Sr4Iaepof5xqStDmRKD0gJy9plWpajn5vt17w2Motz1tO//DHD:5iTRKSsIae+3qADmsoCU4pilt4B//D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124149F12BE90C9F3C550823369272754F61BA6706E105D13ABD11B29AFF3AE78F2560B
sha3_384: d5e7be579658c70814014c42ba282348c118afde455aa71ab86139b910320c427af0745b8787b9bd6e217e2fd694ee3e
ep_bytes: b903000000b8b40000004a2bd04203d1
timestamp: 2020-03-07 14:01:04

Version Info:

0: [No Data]

Ransom.AVCrypt.17 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.AVCrypt.17
ClamAVWin.Malware.Razy-7139871-0
FireEyeGeneric.mg.257b500a2e9c018a
CylanceUnsafe
VIPREGen:Variant.Ransom.AVCrypt.17
SangforSuspicious.Win32.Save.a
K7AntiVirusProxy-Program ( 004a98041 )
K7GWProxy-Program ( 004a98041 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecTrojan.Smallprox
ESET-NOD32a variant of Win32/TrojanProxy.Agent.NYH
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Ransom.AVCrypt.17
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Ransom.AVCrypt.17
EmsisoftGen:Variant.Ransom.AVCrypt.17 (B)
DrWebTrojan.MulDrop20.63325
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ransom.AVCrypt.17
AviraHEUR/AGEN.1237542
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.559C
ArcabitTrojan.Ransom.AVCrypt.17
MicrosoftTrojanDropper:Win32/Bunitu.K!bit
GoogleDetected
AhnLab-V3Trojan/Win32.Bunitu.R299068
BitDefenderThetaGen:NN.ZexaF.34698.muW@ayzhfsai
ALYacGen:Variant.Ransom.AVCrypt.17
VBA32BScope.TrojanRansom.Blocker
MalwarebytesMalware.AI.3685331413
RisingTrojan.Proxy!1.AE83 (CLASSIC)
YandexTrojan.GenAsa!v5bmHqjmCVw
IkarusTrojan-Proxy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NYH!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.a2e9c0
PandaTrj/GdSda.A

How to remove Ransom.AVCrypt.17?

Ransom.AVCrypt.17 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment