Ransom Trojan

Trojan.Ransom.APU malicious file

Malware Removal

The Trojan.Ransom.APU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.APU virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Modifies boot configuration settings
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.APU?


File Info:

crc32: 25451CAB
md5: 1ba9ad23fa2182f7408878545d52fd1e
name: 1BA9AD23FA2182F7408878545D52FD1E.mlw
sha1: 624a0d2cb004d3f1ab1ef0cc308f9453b20ac7ad
sha256: 39b5dd803071ebc4590a51c7d25e15eeddf2f4dcb27950ebfe80c4315432b3c1
sha512: 434c1234aa63d875a402a757afffb3d4ec07beeed1db62321615ff56f3af4e79771e8b98d40a36f510bbc7ddb15a04d2a9bf961a3ec4b4e0e981cbd53eecf631
ssdeep: 12288:CV4sPzhK43pOuoaT/AewoPJ0i22qWmYhK43pOuoaT/AewoP7:Cms7hKuzJwmSi2ruhKuzJwm7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: Signalled
FileVersion: 0.246.63.42
CompanyName: Aluria Software, LLC
PrivateBuild: 15, 247, 170, 109
LegalTrademarks: Unplanned
Comments: Solicitations
ProductName: Shadiest Tequila
SpecialBuild: 0.254.176.19
ProductVersion: 0.98.44.11
FileDescription: Zig Unrests Toilet
OriginalFilename: Theoreticianl.EXE

Trojan.Ransom.APU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3869
CynetMalicious (score: 100)
CAT-QuickHealRansom.Teslacrypt.OL4
ALYacTrojan.Ransom.APU
CylanceUnsafe
ZillyaTrojan.Ransom.Win32.47
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Tescrypt.82d6cad3
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.3fa218
BaiduWin32.Trojan.Filecoder.k
SymantecTrojan.Gen
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.APU
NANO-AntivirusTrojan.Win32.Encoder.eagljg
ViRobotTrojan.Win32.TeslaCrypt.Gen.C
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanTrojan.Ransom.APU
TencentMalware.Win32.Gencirc.10c323b9
Ad-AwareTrojan.Ransom.APU
SophosMal/Generic-R + Mal/Ransom-EK
ComodoMalware@#2p20u1g7fk51g
F-SecureHeuristic.HEUR/AGEN.1124982
BitDefenderThetaGen:NN.ZexaF.34628.Mq0@aG82KMi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionRansom-O.a
FireEyeGeneric.mg.1ba9ad23fa2182f7
EmsisoftTrojan.Ransom.APU (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ngau
WebrootRansom.Telsacrypt.Gen
AviraHEUR/AGEN.1124982
eGambitGeneric.Malware
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Tpyn.v.(kcloud)
MicrosoftRansom:Win32/Tescrypt.H
ArcabitTrojan.Ransom.APU
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.APU
AhnLab-V3Trojan/Win32.Teslacrypt.R174306
Acronissuspicious
McAfeeRansom-O.a
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
RisingTrojan.Ransom-Tesla!1.A322 (CLOUD)
YandexTrojan.Filecoder!K+VHMZrRqZ8
IkarusTrojan-Ransom.CryptoWall3
FortinetW32/Kryptik.EOVH!tr
AVGWin32:Rootkit-gen [Rtk]
Qihoo-360Win32/Ransom.Tescrypt.HwcBEpsA

How to remove Trojan.Ransom.APU?

Trojan.Ransom.APU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment