Ransom Trojan

Should I remove “Trojan.Ransom.AXU”?

Malware Removal

The Trojan.Ransom.AXU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.AXU virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ransom.AXU?


File Info:

crc32: 6686AC3D
md5: ad2536a3560ddb97d6e77e0a3f08a571
name: AD2536A3560DDB97D6E77E0A3F08A571.mlw
sha1: 9e54f8838386a35ecc12ef6f80670bf42135139b
sha256: 9d9fddc7165dc2ae6484c0d25864fbc3466d8933d647b600ff267273611d4a61
sha512: 0370a06496533bbb45b358335fbda91b0c1d22d13cf7b78f8ab8241c2267589baa4b880100e85b6d28ee154422be2b895a4cb718e1961ac9365bfd6f8f546ea6
ssdeep: 3072:8XlWfgzS1rAEsLHGDbyvfPp99n7t3+Y7B0dy/vGUA:8XBzS1rEjGDb+Xp9bz7B0d4GU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 2009
InternalName: clouf
FileVersion: 1, 5, 2, 2
CompanyName: Siber Systems
ProductName: clouf Module
ProductVersion: 1, 5, 2, 2
FileDescription: clouf
OriginalFilename: clouf.exe
Translation: 0x0409 0x04b0

Trojan.Ransom.AXU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f40a91 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.38485
CynetMalicious (score: 100)
ALYacTrojan.Ransom.AXU
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Locky.936202b5
K7GWTrojan ( 004f40a91 )
Cybereasonmalicious.3560dd
BaiduWin32.Trojan.Kryptik.als
SymantecRansom.TeslaCrypt!g7
ESET-NOD32a variant of Win32/Kryptik.FCCT
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Locky-31470
KasperskyTrojan-Ransom.Win32.Locky.anl
BitDefenderTrojan.Ransom.AXU
NANO-AntivirusTrojan.Win32.Locky.fhjgyj
MicroWorld-eScanTrojan.Ransom.AXU
TencentWin32.Trojan.Locky.Lneb
Ad-AwareTrojan.Ransom.AXU
SophosML/PE-A + Troj/Locky-FC
ComodoTrojWare.Win32.TrojanDownloader.Nymaim.DZW@6h3553
BitDefenderThetaGen:NN.ZexaF.34690.hmKfaaRV9ydi
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.BadFile.cc
FireEyeGeneric.mg.ad2536a3560ddb97
EmsisoftTrojan.Ransom.AXU (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Locky.dxd
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.19B4491
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Locky
AegisLabTrojan.Win32.Locky.4!c
GDataTrojan.Ransom.AXU
TACHYONRansom/W32.Locky.139776.W
AhnLab-V3Trojan/Win32.Locky.C3375969
McAfeeGenericRXAA-AA!AD2536A3560D
MAXmalware (ai score=100)
VBA32BScope.Trojan.Ransom
MalwarebytesRansom.Locky
PandaTrj/GdSda.A
RisingRansom.Locky!8.1CD4 (CLOUD)
YandexTrojan.Locky!lrMgWZEQsso
IkarusTrojan-Ransom.Locky
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AP.D8CC!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.Ransom.AXU?

Trojan.Ransom.AXU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment