Ransom Trojan

Trojan.Ransom.ASA removal tips

Malware Removal

The Trojan.Ransom.ASA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.ASA virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Code injection with CreateRemoteThread in a remote process
  • Deletes its original binary from disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Trojan.Ransom.ASA?


File Info:

crc32: 3FB1D242
md5: 2dbe594c2f6ab845b015d7924a7b7692
name: 2DBE594C2F6AB845B015D7924A7B7692.mlw
sha1: d08b6919437beccfa04686b48d0488d94ec86b9b
sha256: 51b386fd3f8866462e026ebd06ca860a3d7c1b01525d6d76b5c9dbff2c59ac50
sha512: a98b9be8e8f5dd5315523056ba1350334cf9e385f747abb8fc634f140a96b736ffede097cfd3b055ab8775c9f1fd7d9e55040829c50dece1441d18b2a39e1b1d
ssdeep: 3072:23fyYowuJw+YYAiRTMAF7SqCtaZWmYbB6UHLww:QoqqWm0cUrV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.ASA also known as:

LionicTrojan.Win32.Bublik.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4084
CAT-QuickHealRansom.Tescrypt.A4
ALYacTrojan.Ransom.ASA
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.878429
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004dffb71 )
K7AntiVirusTrojan ( 004dffb71 )
SymantecPacked.Generic.521
ESET-NOD32a variant of Win32/Kryptik.FCNQ
ZonerTrojan.Win32.38616
APEXMalicious
AvastWin32:Mutex-G [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.ASA
NANO-AntivirusTrojan.Win32.Bitman.eaxlov
MicroWorld-eScanTrojan.Ransom.ASA
TencentMalware.Win32.Gencirc.114bf60b
Ad-AwareTrojan.Ransom.ASA
SophosML/PE-A + Mal/Wonton-CF
ComodoTrojWare.Win32.Yakes.EQJ@6b1mz8
BitDefenderThetaAI:Packer.C66C3A9020
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMA8
McAfee-GW-EditionRansom-Tescrypt!2DBE594C2F6A
FireEyeGeneric.mg.2dbe594c2f6ab845
EmsisoftTrojan.Ransom.ASA (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Bitman.sq
AviraHEUR/AGEN.1107192
Antiy-AVLTrojan/Generic.ASMalwS.177C1FB
MicrosoftVirTool:Win32/CeeInject.GF
GDataTrojan.Ransom.ASA
AhnLab-V3Malware/Win32.RL_Generic.R332415
Acronissuspicious
McAfeeRansom-Tescrypt!2DBE594C2F6A
MAXmalware (ai score=86)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.SMA8
RisingTrojan.Generic@ML.100 (RDML:ytVnnfoW1Laq412qzgrDzw)
IkarusTrojan-Ransom.TeslaCrypt
FortinetW32/Kryptik.EQFO!tr
AVGWin32:Mutex-G [Trj]
Paloaltogeneric.ml

How to remove Trojan.Ransom.ASA?

Trojan.Ransom.ASA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment