Ransom

Ransom.Troldesh.10 (file analysis)

Malware Removal

The Ransom.Troldesh.10 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Troldesh.10 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Troldesh.10?


File Info:

crc32: B91440D9
md5: 42c28bdb4460796fd0b2d35e79f4f844
name: 42C28BDB4460796FD0B2D35E79F4F844.mlw
sha1: c20b9f5fedbbb81ad2000ae43c5305e2b03419c1
sha256: 280ed3f826d32f728c4943b29f84470d3a542a5960f94a7fa0851028ed6aa905
sha512: 7b8ef11ab52cb4205bb13dd1a35d6634c5fcab231f9aebf54a6519d31ab607eaff24d5c6e94279f8512f5bb6ea290bba3c98364e2079aee910dc3fc2dc71b186
ssdeep: 6144:QTHTel7oR6fDqKRJ1WSJQpj/dbZ1QcAXA:4el7teKRJ17Jc/BQce
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Ransom.Troldesh.10 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056fe921 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.44949
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Troldesh.10
CylanceUnsafe
ZillyaTrojan.Crusis.Win32.159
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Injector.7ba1196c
K7GWTrojan ( 0056fe921 )
Cybereasonmalicious.b44607
CyrenW32/Trojan.WBCJ-3538
SymantecRansom.Cerber!g17
ESET-NOD32a variant of Win32/Injector.DLCB
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Troldesh.10
NANO-AntivirusTrojan.Win32.Crusis.elnncm
MicroWorld-eScanGen:Variant.Ransom.Troldesh.10
TencentMalware.Win32.Gencirc.11494b3a
Ad-AwareGen:Variant.Ransom.Troldesh.10
SophosMal/Isda-D
BitDefenderThetaGen:NN.ZexaF.34608.mmZfay1NPlie
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYSIS.F117BD
McAfee-GW-EditionBehavesLike.Win32.Gupboot.cc
FireEyeGeneric.mg.42c28bdb4460796f
EmsisoftGen:Variant.Ransom.Troldesh.10 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Ransomware.Cerber
AviraHEUR/AGEN.1127362
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Cerber!rfn
AegisLabTrojan.Win32.Crusis.j!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Troldesh.10
McAfeeRansomware-FLWW!42C28BDB4460
MAXmalware (ai score=88)
MalwarebytesMalware.Heuristic.1001
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYSIS.F117BD
RisingRansom.Crusis!8.5724 (CLOUD)
IkarusTrojan.Win32.Filecoder
FortinetW32/Generic.AC.3CE5D9!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxEAar8A

How to remove Ransom.Troldesh.10?

Ransom.Troldesh.10 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment