Ransom

Ransom.Locky.173 (B) removal instruction

Malware Removal

The Ransom.Locky.173 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Locky.173 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ransom.Locky.173 (B)?


File Info:

crc32: C2E53B5E
md5: e6529aa605040905ce0ebdcd35fa9daf
name: E6529AA605040905CE0EBDCD35FA9DAF.mlw
sha1: 6af326a3b3f1772cdd3299f4980f32f71c4fffd9
sha256: a77cd9396ec3a31f325812fe07f430a7a54f37371554dbe0c8f902d10f1631be
sha512: 1a9e9fb6ad118533cc2dea74aecb29614cccdcaf66d1725d5eef5d100575be86f6d76c8217550e3236a491567ace1efd9f2e2e06f3c15d038ea15985b7d35855
ssdeep: 3072:+IoiR09T6gpFghrwfJ7iObICsfATWNDHmwQjyT83naF+FeM6AJnoMWmeRYi72:iZ6gHgydhTWhHcNW9M6wnha
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Locky.173 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00515aa21 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.13122
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.A5
ALYacGen:Variant.Ransom.Locky.173
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.3444
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Cerber.6abefdc7
K7GWTrojan ( 00512d421 )
Cybereasonmalicious.605040
CyrenW32/S-d3448d8a!Eldorado
SymantecPacked.Generic.493
ESET-NOD32Win32/Filecoder.Cerber.P
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Generickdz-6905769-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.pef
BitDefenderGen:Variant.Ransom.Locky.173
NANO-AntivirusTrojan.Win32.Zerber.erftmx
MicroWorld-eScanGen:Variant.Ransom.Locky.173
TencentMalware.Win32.Gencirc.10b32cd6
Ad-AwareGen:Variant.Ransom.Locky.173
ComodoTrojWare.Win32.Ransom.Cerber.AB@76dn5e
BitDefenderThetaGen:NN.ZexaF.34722.ouW@aCRVEhfi
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.e6529aa605040905
EmsisoftGen:Variant.Ransom.Locky.173 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.cxg
AviraTR/Crypt.XPACK.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.215112E
MicrosoftRansom:Win32/Cerber.L!bit
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ransom.Locky.173
AhnLab-V3Trojan/Win32.Cerber.R205028
Acronissuspicious
McAfeeRansomware-GDA!E6529AA60504
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMALY0
RisingTrojan.Generic@ML.100 (RDML:AWrlx9iBZ/cbhHiYC74uJA)
YandexTrojan.GenAsa!slOsR0StOdE
IkarusTrojan.Win32.Filecoder
FortinetW32/Kryptik.GLXU!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.Locky.173 (B)?

Ransom.Locky.173 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment