Ransom

How to remove “Ransom:Win32/Avaddon”?

Malware Removal

The Ransom:Win32/Avaddon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Avaddon virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Checks for the presence of known windows from debuggers and forensic tools
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to disable UAC
  • Attempts to ensure mapped drives are available from an elevated prompt or process with UAC enabled
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ransom:Win32/Avaddon?


File Info:

name: 7EE92C094DE8CADE29D9.mlw
path: /opt/CAPEv2/storage/binaries/104b8c43fcc751fc0a349cfac16236236f9c3e11eba2c8a920ebad7877b39a18
crc32: B5E856BF
md5: 7ee92c094de8cade29d9e8e3ef690320
sha1: d27c279a20caf9c00963c936356834d7830bac04
sha256: 104b8c43fcc751fc0a349cfac16236236f9c3e11eba2c8a920ebad7877b39a18
sha512: 0fbcd3aecf24ed826b9266ccb1916b229f238994239df863dd220936de6c5ba398e50cdfb954b51b65c9fa4031b43300313fce8bbc8205af7b36161a99cdf5c9
ssdeep: 98304:QOV9Uro56gHLgkixdykidSESW6R4gXW2zo2kJHzQNa:fV9Uro4JVxPES7RFvCJHzQNa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E3633A0A6D5ACC5CB8E47767C27C2063AB4A0763F49B473044F19721CD9E9C6BB0BE5
sha3_384: 73a85fa49ed09e9cef08f6e54da5e378766868216213e8806d62f0fb484c15d9983c8d978fab3cfcd0d06cfdb5a519cc
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2021-05-28 19:53:46

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Host Process for Windows Tasks
FileVersion: 10.0.17763.831 (WinBuild.160101.0800)
InternalName: taskhost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: taskhost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17763.831
Translation: 0x0409 0x04b0

Ransom:Win32/Avaddon also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Malicious.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.37102041
FireEyeGeneric.mg.7ee92c094de8cade
McAfeeArtemis!7EE92C094DE8
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/DelShad.07b5b90c
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a20caf
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Filecoder.Avaddon.F
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.DelShad.gjc
BitDefenderTrojan.GenericKD.37102041
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Malware-gen
TencentWin32.Trojan.Filecoder.Gjgl
EmsisoftTrojan.GenericKD.37102041 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
VIPRETrojan.GenericKD.37102041
McAfee-GW-EditionBehavesLike.Win32.Expiro.rc
Trapminemalicious.high.ml.score
SophosMal/FakeMS-X
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.37102041
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Ransom]/Win32.Avaddon
ArcabitTrojan.Generic.D23621D9
ZoneAlarmTrojan.Win32.DelShad.gjc
MicrosoftRansom:Win32/Avaddon
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4527986
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36196.@V0@amJl1zpi
ALYacTrojan.Ransom.Avaddon
MAXmalware (ai score=100)
VBA32BScope.Trojan.DelShad
MalwarebytesRansom.Avaddon
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.98 (RDML:KXtcLYRf4/E6XrmoggCKIQ)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.191545996.susgen
FortinetW32/DelShad.F!tr.ransom
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/Avaddon?

Ransom:Win32/Avaddon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment