Ransom Trojan

Trojan.Ransom.AHX removal

Malware Removal

The Trojan.Ransom.AHX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.AHX virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Ransom.AHX?


File Info:

crc32: 1965FABD
md5: 00cb45c4efd4053cef8bb8567dc0638e
name: 00CB45C4EFD4053CEF8BB8567DC0638E.mlw
sha1: db0793c3b395697495e89460c35b0b3947c028f1
sha256: 005d62ccb914fe69ed4795a68a2ec0c679e4713c50a73d90524b7bac1240fefd
sha512: 1b59c609c1ea2f548a70d8f18df7bb2798c565c7517f24050f1496d36bbe9e7aa63523dea1ac96ff7e018c7c0d26983076eceefc2b1eca1486ef8a7e047f4417
ssdeep: 6144:PkaIRAN6/PehvUcyKD3angGcQtgZf2JQ31ONbN+i1v153e5OKw+3psIHcR:PqRL/GhvYlco+eyFO7+izao
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2011
InternalName: HD Tune Pro
FileVersion: 5, 0, 0, 0
CompanyName: EFD Software
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: HD Tune Pro
SpecialBuild:
ProductVersion: 5, 0, 0, 0
FileDescription: HD Tune Pro
OriginalFilename: HDTunePro.EXE
Translation: 0x0409 0x04b0

Trojan.Ransom.AHX also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
CynetMalicious (score: 100)
CAT-QuickHealRansom.ChaCha.S6205083
ALYacTrojan.Ransom.AHX
CylanceUnsafe
ZillyaTrojan.Crypren.Win32.138
SangforRansom.Win32.Teerac.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Teerac.2bb80493
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.4efd40
SymantecRansom.TorrentLocker
ESET-NOD32Win32/Filecoder.TorrentLocker.A
ZonerTrojan.Win32.27529
APEXMalicious
AvastWin32:Teerac-I [Trj]
ClamAVWin.Trojan.Generickdz-7779688-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.AHX
NANO-AntivirusTrojan.Win32.Rack.djzytd
ViRobotTrojan.Win32.Ransom.592384
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
MicroWorld-eScanTrojan.Ransom.AHX
Ad-AwareTrojan.Ransom.AHX
SophosTroj/Ransom-AOI
ComodoMalware@#m68bht8midfa
BitDefenderThetaGen:NN.ZexaF.34692.Cq0@auayDHei
VIPRETrojan.Win32.CryptoWall.gen
TrendMicroTROJ_CRYPDEF.WAN
McAfee-GW-EditionPWS-FBYY!00CB45C4EFD4
FireEyeGeneric.mg.00cb45c4efd4053c
EmsisoftTrojan.Ransom.AHX (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Crypren.da
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1131598
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.D3338B
MicrosoftRansom:Win32/Teerac.A
ArcabitTrojan.Ransom.AHX
AegisLabTrojan.Win32.Shiotob.tpqZ
GDataTrojan.Ransom.AHX
TACHYONRansom/W32.Crypren.465920
AhnLab-V3Spyware/Win32.Zbot.R128181
McAfeePWS-FBYY
MAXmalware (ai score=100)
VBA32Hoax.Crypren
MalwarebytesTrojan.Pseudo
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_CRYPDEF.WAN
RisingRansom.Teerac!8.57A (TFE:1:s8ciDSy7w5B)
YandexTrojan.GenAsa!+Joh5Vfq59U
IkarusTrojan-Ransom.Crypren
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/TorrentLocker.A!tr.ransom
AVGWin32:Teerac-I [Trj]
Paloaltogeneric.ml

How to remove Trojan.Ransom.AHX?

Trojan.Ransom.AHX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment