Ransom

About “Ransom:Win32/Troldesh.A!bit” infection

Malware Removal

The Ransom:Win32/Troldesh.A!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Troldesh.A!bit virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Troldesh.A!bit?


File Info:

crc32: E5A4209F
md5: 985458b52c78c0ee2356cc25172f7277
name: sserv.jpg
sha1: fc487008021692b99267447bb9ac73755cfa2997
sha256: 981e0d084f78e268294fe3c0a5ecc4869bb189aff927a6b6a5da0cad61b4fca4
sha512: 4ebfe198bd474fdb8a7d282cd52442f2cc00bf3a636cb6efc40e4b98a780eabb0efd2f3a7e872857e5190aa6f4ab73d940c2935fedacec22e7b265ff96cda66d
ssdeep: 24576:AinBv073hiuK+BP9lbifbKw1ohJkdV4KrY:Am0jsuKWlmOrhJIV4d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014 AVG Technologies CZ, s.r.o.
InternalName: VistaAux.exe
FileVersion: 17.3.3443.0
CompanyName: AVG Technologies CZ, s.r.o.
ProductName: AVG Internet Security System
ProductVersion: 17.3.3443.0
FileDescription: AVG Virus scanner
OriginalFilename: VistaAux.exe
Translation: 0x0409 0x04e4

Ransom:Win32/Troldesh.A!bit also known as:

MicroWorld-eScanTrojan.GenericKD.31361640
FireEyeGeneric.mg.985458b52c78c0ee
CAT-QuickHealTrojan.IGENERIC
McAfeeGeneric.buc
MalwarebytesRansom.FileCryptor
VIPREWin32.Malware!Drop
AegisLabTrojan.Win32.Shade.tpKI
K7AntiVirusTrojan ( 004b8aa51 )
BitDefenderTrojan.GenericKD.31361640
K7GWTrojan ( 004b8aa51 )
Cybereasonmalicious.52c78c
Invinceaheuristic
F-ProtW32/Shade.O
SymantecDownloader
APEXMalicious
Paloaltogeneric.ml
GDataWin32.Trojan-Ransom.Shade.3A1UFU
KasperskyTrojan-Ransom.Win32.Shade.pbx
AlibabaRansom:Win32/Shade.fdcd1b64
NANO-AntivirusTrojan.Win32.Shade.fkklvp
ViRobotTrojan.Win32.S.Ransom.1066248.A
RisingRansom.Troldesh!8.5D1 (KTSE)
Ad-AwareTrojan.GenericKD.31361640
SophosTroj/Xtbl-BD
ComodoMalware@#da0t3rgfpq7f
F-SecureTrojan.TR/FileCoder.AJ
DrWebTrojan.Encoder.26601
ZillyaTrojan.Shade.Win32.871
TrendMicroTROJ_FRS.0NA103KK18
McAfee-GW-EditionGeneric.buc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.31361640 (B)
IkarusRansom.Win32.Troldesh
CyrenW32/Trojan.EIIA-8447
JiangminTrojan.Shade.rv
WebrootW32.Adware.Gen
AviraTR/FileCoder.AJ
Antiy-AVLTrojan[Ransom]/Win32.Shade
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1DE8A68
SUPERAntiSpywareRansom.MalPack/Variant
ZoneAlarmTrojan-Ransom.Win32.Shade.pbx
MicrosoftRansom:Win32/Troldesh.A!bit
AhnLab-V3Malware/Win32.RL_Generic.R264656
Acronissuspicious
VBA32BScope.TrojanRansom.Shade
ALYacTrojan.Ransom.Shade
MAXmalware (ai score=100)
CylanceUnsafe
PandaTrj/WLT.E
ZonerTrojan.Win32.74252
ESET-NOD32Win32/Filecoder.Shade.B
TrendMicro-HouseCallTROJ_FRS.0NA103KK18
YandexTrojan.Shade!
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Shade.BD!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.Ransom.d4b

How to remove Ransom:Win32/Troldesh.A!bit?

Ransom:Win32/Troldesh.A!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment