Ransom Trojan

How to remove “Trojan-Ransom.Win32.Cryptodef.bvj”?

Malware Removal

The Trojan-Ransom.Win32.Cryptodef.bvj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptodef.bvj virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Cryptodef.bvj?


File Info:

name: E643990606136F76DD3F.mlw
path: /opt/CAPEv2/storage/binaries/d76dd274ae1e0c0cb5f3ef43f0b4908280598846aa73bbcdbe54265017439910
crc32: F8D8459E
md5: e643990606136f76dd3fbc5faa6b2072
sha1: e7769b2c99db2ea0d10ceabce4822113b6984e51
sha256: d76dd274ae1e0c0cb5f3ef43f0b4908280598846aa73bbcdbe54265017439910
sha512: 0bbbacdfd525c481963cffbd37c2823e9c2f274075f234a11de1aafce8468b03e395d11862fb50c8a49054f7fd44b6ebefd5c37be6a2615a2a8dfdb353f09c2d
ssdeep: 384:N9xdUqG1E/ew1Zz/aH59N1Drb+E1H63Vs17o/Wsd:PxdIm/hZGHrqE1H63A7o/Ws
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144A2C4B773D24CF5F6A307B0A876624BA49074D153D236FF4A1E9E104902AC6EAF12C9
sha3_384: 852875f5f924bd70d48e6315ed891815c1f0da5a9ed922a610d3a215da98728ed36adbd1f8bfd6c1e3e1a6506191a2ad
ep_bytes: 558bec83ec4456ff150c2040008bf08a
timestamp: 1992-06-01 18:44:46

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptodef.bvj also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e643990606136f76
CAT-QuickHealTrojanDownloader.Upatre.AA4
ALYacTrojan.GenericKD.1796217
CylanceUnsafe
ZillyaTrojan.Cryptodef.Win32.125
K7AntiVirusTrojan-Downloader ( 0048f6391 )
BitDefenderTrojan.GenericKD.1796217
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.606136
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Generic.CNGO
CyrenW32/Trojan.INCI-3183
SymantecRansom.Cryptodefense
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyTrojan-Ransom.Win32.Cryptodef.bvj
NANO-AntivirusTrojan.Win32.Panda.ddsitr
MicroWorld-eScanTrojan.GenericKD.1796217
RisingDownloader.Waski!1.A489 (RDMK:cmRtazoyKcjAlwSwiYxN0tQLP2n9)
SophosML/PE-A + Troj/Ransom-AKD
ComodoTrojWare.Win32.TrojanDownloader.Waski.DA@5iyglc
DrWebTrojan.PWS.Panda.7591
VIPRETrojan.Win32.Upatre.buu (v)
TrendMicroTROJ_UPATRE.SMN6
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
EmsisoftTrojan.GenericKD.1796217 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cryptodef.ag
AviraTR/ATRAPS.A.1656
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Zbot.svfs!MTB
SUPERAntiSpywareTrojan.Agent/Gen-KD
ZoneAlarmTrojan-Ransom.Win32.Cryptodef.bvj
GDataWin32.Trojan-Downloader.Upatre.BK
AhnLab-V3Dropper/Win32.Necurs.R115439
BitDefenderThetaGen:NN.ZexaF.34182.bqX@aiLlmVgO
VBA32BScope.TrojanPSW.Panda
MalwarebytesMalware.AI.2456335957
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMN6
TencentTrojan.Win32.Downloader.bvj
YandexTrojan.Cryptodef!/wlz6YFVXN4
IkarusTrojan.Win32.Bublik
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr.dldr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Ransom.Win32.Cryptodef.bvj?

Trojan-Ransom.Win32.Cryptodef.bvj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment