Ransom Trojan

Trojan.Ransom.DeathWing (A) malicious file

Malware Removal

The Trojan.Ransom.DeathWing (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.DeathWing (A) virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Trojan.Ransom.DeathWing (A)?


File Info:

crc32: A41F50E4
md5: e6794ee0150e636b519ffd8426421153
name: E6794EE0150E636B519FFD8426421153.mlw
sha1: 9990cb21ae504c4c5f119031cb77611c2f8f0072
sha256: d3726b6aa2482299c63787b75e5a8174b03d304985ec7a63cd0a9bb8b8768309
sha512: ab45f518558779e3ae8f8c3a94b26f8a2b071faae780320111222b25fed84352e7bed116fed5f66dfd7d3dac6d411c2054729446af81a18bdf20e3f37e6224c1
ssdeep: 192:F9Suks7TRXXsqmNPCz+mxA5h5oDh9QLIR1ftlQKFVPhLtbbf3Di:bn9X4PCfA5DoDHA8IiXvf3D
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: DeathWing.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: DeathWing
ProductVersion: 1.0.0.0
FileDescription: DeathWing
OriginalFilename: DeathWing.exe

Trojan.Ransom.DeathWing (A) also known as:

DrWebTrojan.Encoder.24649
ClamAVWin.Ransomware.Hiddentear-9752356-0
ALYacTrojan.Ransom.GenericKD.30351040
CylanceUnsafe
ZillyaTrojan.Injector.Win32.530116
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004cd60c1 )
K7AntiVirusTrojan ( 004cd60c1 )
SymantecRansom.HiddenTear!g1
ESET-NOD32a variant of MSIL/Filecoder.Y
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.GenericKD.30351040
NANO-AntivirusTrojan.Win32.Filecoder.eycwht
MicroWorld-eScanTrojan.Ransom.GenericKD.30351040
TencentWin32.Trojan.Generic.Akez
Ad-AwareTrojan.Ransom.GenericKD.30351040
SophosMal/Cryptear-A
ComodoMalware@#t1em2gvkz3m6
BitDefenderThetaGen:NN.ZemsilF.34142.am0@aakEOEj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-FTD!E6794EE0150E
FireEyeGeneric.mg.e6794ee0150e636b
EmsisoftTrojan.Ransom.DeathWing (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dpsec
AviraHEUR/AGEN.1117207
Antiy-AVLTrojan/Generic.ASMalwS.2485B1D
MicrosoftRansom:MSIL/Ryzerlo.A
GDataMSIL.Trojan-Ransom.Cryptear.R
AhnLab-V3Trojan/Win32.Ransom.R223459
McAfeeRansomware-FTD!E6794EE0150E
MAXmalware (ai score=99)
VBA32TrojanRansom.MSIL.Ryzerlo
MalwarebytesRansom.HiddenTear
PandaTrj/GdSda.A
YandexTrojan.Agent!KW7uCGgeL00
IkarusTrojan-Ransom.FileCrypter
FortinetMSIL/Filecoder.AK!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Ransom.DeathWing (A)?

Trojan.Ransom.DeathWing (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment