Ransom

Should I remove “Ransom.Troldesh”?

Malware Removal

The Ransom.Troldesh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Ransom.Troldesh virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ransom.Troldesh?


File Info:

crc32: 720746EF
md5: e99a6653e12d6b676a8984380b387a15
name: 2c.jpg
sha1: 3c17b6a7e1f0d3be71cfa185d8866f7caccbeb46
sha256: 6556303d76c57a172c38ce49630acbceb6b5fb9f033a9ff0c3d1ad5668269c32
sha512: e908819771ba6eabb61433c65763593eb941554f677784657f4409cc51c7c342542e02bc2fe54caff9e3f3044ea993d29abfef499723a68222ed37cba1227941
ssdeep: 24576:zroIU88zqtrXk/VVDJAjqQDFp/a10tYXob:zrH58mtr0Z0dhpWqb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileOldVersion: 1.0.4.4
ProductVersion: 1.7.6
Copyrighd: Copyrighd (C) 2020, odfgbiv
InternalNameTwo: gjtrrh.exe
Translation: 0x0841 0x04c4

Ransom.Troldesh also known as:

DrWebTrojan.Encoder.858
MicroWorld-eScanTrojan.GenericKD.32727374
FireEyeGeneric.mg.e99a6653e12d6b67
CAT-QuickHealRansom.Troldesh
McAfeeRansomware-GRA!E99A6653E12D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.TorTool.1!c
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.32727374
K7GWTrojan ( 0055bbd91 )
K7AntiVirusTrojan ( 0055bbd91 )
TrendMicroTROJ_FRS.VSNW12K19
BitDefenderThetaGen:NN.ZexaF.32515.@y0@a4KyS0b
SymantecDownloader
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Dropper.Tofsee-7402230-0
GDataTrojan.GenericKD.32727374
Kasperskynot-a-virus:NetTool.Win32.TorTool.abh
NANO-AntivirusTrojan.Win32.Encoder.gixgyo
ViRobotTrojan.Win32.Z.Wacatac.1036800.C
RisingTrojan.Kryptik!1.BE74 (CLASSIC)
Ad-AwareTrojan.GenericKD.32727374
SophosTroj/Ransom-FSI
ComodoMalware@#25wk32zyd6437
F-SecureTrojan.TR/AD.Troldesh.vauvq
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.moderate.ml.score
IkarusTrojan-Downloader.Win32.SmokeLoader
CyrenW32/Trojan.DLBN-3946
JiangminNetTool.TorTool.ax
WebrootW32.Trojan.GenKD
AviraTR/AD.Troldesh.vauvq
Antiy-AVLRiskWare[NetTool]/Win32.TorTool
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F3614E
ZoneAlarmnot-a-virus:NetTool.Win32.TorTool.abh
MicrosoftTrojan:Win32/GandCrypt.GB!MTB
AhnLab-V3Trojan/Win32.MalPe.R299953
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacTrojan.Ransom.Shade
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GYNN
TrendMicro-HouseCallTROJ_FRS.VSNW12K19
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.74701925.susgen
FortinetMalicious_Behavior.SB
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.7e1f0d
Qihoo-360Win32/Virus.NetTool.0be

How to remove Ransom.Troldesh?

Ransom.Troldesh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment