Trojan

What is “Trojan.Polyransom”?

Malware Removal

The Trojan.Polyransom is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Polyransom virus can do?

  • Authenticode signature is invalid

How to determine Trojan.Polyransom?


File Info:

name: E7E5EAABFA8A40EFE8AF.mlw
path: /opt/CAPEv2/storage/binaries/ed51e81f0d6e580f42bd4c695b8ccbd4336a7df4a6802312f1601f326d94c325
crc32: 3AF4CB4E
md5: e7e5eaabfa8a40efe8af9f6699e545a3
sha1: 671644bb4c94c1cdd7240fe1094a159e80aa6714
sha256: ed51e81f0d6e580f42bd4c695b8ccbd4336a7df4a6802312f1601f326d94c325
sha512: 2feda0b9879effde2c88d7e4d8275c131d5a739bef5a683e3850402eca3ee5edc6695e00a4607fcb7566c98364c14c876d39544917a3623e5bb9787d9f0a7979
ssdeep: 768:LtxVDwEC+0aj3fUHbOaTsNGYnZh7L1ZpA98ZydalfuV3lVwY3A4Q:LTVDwT5SrnZh7L1XA98OaFufVwsrQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D030908BBAF4115E0BBEFF838FCA5998DF6F61A1405F52B1441068B5D52F42CE1367A
sha3_384: d43ee1908c138a402f0968ab0572b817dd8046d6e74eaa68e06f809ac9e708fbb890799013a7d5ae8a98c06d536ec549
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-04-17 18:28:08

Version Info:

Translation: 0x0000 0x04b0
Comments: CmRccService
FileDescription: CmRccService
FileVersion: 6.1.2.1
InternalName: Vr5AVruriTybtF6
LegalCopyright:
OriginalFilename: Vr5AVruriTybtF6
ProductName: CmRccService
ProductVersion: 6.1.2.1
Assembly Version: 6.1.2.1

Trojan.Polyransom also known as:

LionicTrojan.Win32.PolyRansom.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.23258
ClamAVWin.Packed.Msilzilla-9953300-0
FireEyeGeneric.mg.e7e5eaabfa8a40ef
CAT-QuickHealTrojan.Polyransom
ALYacIL:Trojan.MSILZilla.23258
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005955001 )
AlibabaTrojan:MSIL/Polyransom.e2df99d8
K7GWTrojan ( 005955001 )
Cybereasonmalicious.b4c94c
BitDefenderThetaGen:NN.ZemsilF.36196.cm0@a4RhgRo
VirITTrojan.Win32.MSIL_Heur.A
ESET-NOD32a variant of MSIL/Agent.VIF
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderIL:Trojan.MSILZilla.23258
F-SecureHeuristic.HEUR/AGEN.1305561
VIPREIL:Trojan.MSILZilla.23258
TrendMicroRansom_PolyRansom.R002C0DE423
Trapminemalicious.high.ml.score
SophosMal/DownLdr-FL
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1305561
Antiy-AVLTrojan[Ransom]/MSIL.PolyRansom
ArcabitIL:Trojan.MSILZilla.D5ADA
ZoneAlarmHEUR:Trojan-Ransom.MSIL.PolyRansom.gen
GDataIL:Trojan.MSILZilla.23258
GoogleDetected
AhnLab-V3Trojan/Win.Mardom.C5109384
Acronissuspicious
VBA32OScope.Trojan.MSIL.Basic.8
MAXmalware (ai score=88)
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_PolyRansom.R002C0DE423
TencentTrojan-Ransom.MSIL.PolyRansom.16000547
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.VIF!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Polyransom?

Trojan.Polyransom removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment