Ransom Trojan

Dropped:Trojan.Ransom.BHT removal

Malware Removal

The Dropped:Trojan.Ransom.BHT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Ransom.BHT virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Enumerates user accounts on the system
  • Creates RWX memory
  • Reads data out of its own binary image
  • Exhibits behavior characteristic of Cerber ransomware
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Dropped:Trojan.Ransom.BHT?


File Info:

crc32: C6BDCD9B
md5: 58a6b006735e7d5c6fadeb3a0f62ff60
name: 58A6B006735E7D5C6FADEB3A0F62FF60.mlw
sha1: ac4748601e5f0fa934b9357140f86b249ab799df
sha256: 906ee3e3afc35eddf464ccd526cbb525ea52fb88400da56f10802405b6b02bc5
sha512: 228ac15c9b250ae0d22a9c44e40e243180c4ede73ac794615ba6da14fd696c24b3ff011b56276fda1972b2697aaeb16c58246507b00a69f05112847a6ad5bdfd
ssdeep: 6144:/B+pgUPba9nsYY5wrhVBHsvVTG4eZJA4Gu9U45I/i/Pxm:/g3batsCVBHsNTG4IA4GOUiIiPU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: John T. Haller
InternalName: KeePass Portable
FileVersion: 1.5.3.0
CompanyName: PortableApps.com
LegalTrademarks: PortableApps.com is a Trademark of Rare Ideas, LLC.
Comments: Allows KeePass to be run from a removable drive. For additional details, visit PortableApps.com/KeePassPortable
ProductName: KeePass Portable
ProductVersion: 1.5.3.0
FileDescription: KeePass Portable
Translation: 0x0409 0x04b0

Dropped:Trojan.Ransom.BHT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005018cd1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.B
ALYacDropped:Trojan.Ransom.BHT
CylanceUnsafe
SangforTrojan.Win32.Zerber.m
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005018cd1 )
Cybereasonmalicious.6735e7
CyrenW32/Cerber.JDNP-8714
SymantecRansom.Cerber
ESET-NOD32NSIS/Injector.OY
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.ewsw
BitDefenderDropped:Trojan.Ransom.BHT
NANO-AntivirusTrojan.Nsis.Zerber.ekfnqi
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanDropped:Trojan.Ransom.BHT
TencentWin32.Trojan.Raas.Auto
Ad-AwareDropped:Trojan.Ransom.BHT
VIPRETrojan.Win32.Generic!BT
TrendMicroPossible_Cerber-13
McAfee-GW-EditionBehavesLike.Win32.ICLoader.dc
FireEyeGeneric.mg.58a6b006735e7d5c
EmsisoftDropped:Trojan.Ransom.BHT (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117992
MicrosoftRansom:Win32/Cerber!rfn
ArcabitTrojan.Ransom.BHT
AegisLabTrojan.Win32.Zerber.j!c
GDataDropped:Trojan.Ransom.BHT
TACHYONRansom/W32.Cerber.297509
AhnLab-V3Trojan/Win32.Cerber.C1729888
McAfeeArtemis!58A6B006735E
MAXmalware (ai score=99)
VBA32TrojanRansom.Zerber
PandaTrj/Genetic.gen
TrendMicro-HouseCallPossible_Cerber-13
RisingTrojan.Win32.Zerber.m (CLASSIC)
IkarusTrojan-Ransom.Agent
FortinetW32/Injector.OV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HyoDEpsA

How to remove Dropped:Trojan.Ransom.BHT?

Dropped:Trojan.Ransom.BHT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment