Ransom

Ransom.Troldesh.200 removal

Malware Removal

The Ransom.Troldesh.200 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Troldesh.200 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system

How to determine Ransom.Troldesh.200?


File Info:

crc32: E13CEFCE
md5: b0eb8778ade5cd087a2774c0cfd337cd
name: B0EB8778ADE5CD087A2774C0CFD337CD.mlw
sha1: ffb337f682c32b19cea20e6f7749d79eae58cc00
sha256: 151e9dbe5c9396251c70f6deb1b86e8d7632e5398ce275aafa68ae9df14abdb4
sha512: 7440756210180cb846778cb872bfd374cb20da6efb8b1d369f1c8c7f1fde726eaf8a0c6c334317fbb4adaaebddf57289d9ea3459cdf8eca4e5908b03e91b1e27
ssdeep: 6144:Vtn9AAD3Y7Urp9I/3gci3HzAjW9psFXQOnP6vNz3:VFY7UV9I/3gcPC9CnP6h3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2006-2014
InternalName: Filename
FileVersion: 2.9.59.785
CompanyName: DivX, LLC
PrivateBuild: 2.9.59.785
LegalTrademarks: Copyright (c) 2006-2014
Comments: Intptr_t Beanshell
ProductName: Filename
Languages: English
ProductVersion: 2.9.59.785
FileDescription: Intptr_t Beanshell
OriginalFilename: Filename
Translation: 0x0409 0x04b0

Ransom.Troldesh.200 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056e9441 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Troldesh.200
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0056e9441 )
Cybereasonmalicious.8ade5c
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.FNZG
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan.Win32.Yakes.sb
BitDefenderGen:Variant.Ransom.Troldesh.200
MicroWorld-eScanGen:Variant.Ransom.Troldesh.200
TencentWin32.Trojan.Crypt.Pftb
Ad-AwareGen:Variant.Ransom.Troldesh.200
SophosML/PE-A
ComodoMalware@#31iksk3toqkrj
BitDefenderThetaGen:NN.ZexaF.34170.ry0@aWr4Lwgi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_MiliCry-1h
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.b0eb8778ade5cd08
EmsisoftGen:Variant.Ransom.Troldesh.200 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.22DD8C5
MicrosoftVirTool:Win32/Obfuscator.ALX
ArcabitTrojan.Ransom.Troldesh.200
GDataGen:Variant.Ransom.Troldesh.200
Acronissuspicious
McAfeeArtemis!B0EB8778ADE5
MAXmalware (ai score=97)
PandaGeneric Suspicious
TrendMicro-HouseCallMal_MiliCry-1h
RisingTrojan.Generic@ML.100 (RDML:XLRyKT8snGA94Y/2bM9A7w)
IkarusTrojan-Ransom.Crypter
FortinetW32/Kryptik.FNNB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.Troldesh.200?

Ransom.Troldesh.200 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment