Ransom Trojan

Trojan.Ransom.EA information

Malware Removal

The Trojan.Ransom.EA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.EA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.EA?


File Info:

name: CF76BC5036E3B1669FC8.mlw
path: /opt/CAPEv2/storage/binaries/65988565f61af93bbeffe75f0dd6cd406d850911b4093d7abc4f36eeaff988cb
crc32: F080E995
md5: cf76bc5036e3b1669fc818d566f7ce59
sha1: 0b08a87416746c56b0002ce56b26d94cbac6a1d8
sha256: 65988565f61af93bbeffe75f0dd6cd406d850911b4093d7abc4f36eeaff988cb
sha512: dea40a3d118758e3b27b745c3b297f30598bb4ebe6fdc39504b59e4ecff68330d8cebbe136defc1065f4efd6821933c8f1bdd3920978a6520a8199504aaf02ce
ssdeep: 1536:l1d2mwXyTcE/11GxU2XzKxZWvifeKCMpoueetQjvvs9Gqu2D:l1GyTcEqxPjKxE6fFnpxeRrvh2D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13853F242AFB91093DAA77FFD556E20605937727024804F86E88BB84E29D66D152703FF
sha3_384: b38fdbec7c2ef721b74e964068343f1e2cdd7f55e47fc229c954737042e5bbc40572245fa5a2776627680da08604e309
ep_bytes: 60be00f040008dbe0020ffffc78708f0
timestamp: 2005-11-30 04:01:58

Version Info:

Comments: Myth
CompanyName: Pinnacle Systems
FileDescription: Dead
FileVersion: 10.9
InternalName: Stroll Fetus Verne Web
LegalCopyright: Misty © Mile Strafe 1995-2009
OriginalFilename: Epsom.exe
ProductName: Josh Nods Chump Ovals Crass Carl
ProductVersion: 10.9
Translation: 0x0409 0x04b0

Trojan.Ransom.EA also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lh2q
Elasticmalicious (moderate confidence)
DrWebTrojan.Packed.22288
MicroWorld-eScanTrojan.Ransom.EA
FireEyeGeneric.mg.cf76bc5036e3b166
ALYacTrojan.Ransom.EA
CylanceUnsafe
VIPRETrojan.Ransom.EA
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f1000f011 )
AlibabaRansom:Win32/PornoAsset.c1554737
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.036e3b
BitDefenderThetaGen:NN.ZexaF.34646.dmKfaa6UJ6fi
CyrenW32/Ransom.EZYI-4471
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AJN
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.PornoAsset.cqjj
BitDefenderTrojan.Ransom.EA
NANO-AntivirusTrojan.Win32.Birele.hujbi
SUPERAntiSpywareTrojan.Agent/Gen-Figler
TencentWin32.Trojan.Lockscreen.Rgil
Ad-AwareTrojan.Ransom.EA
EmsisoftTrojan.Ransom.EA (B)
ComodoTrojWare.Win32.TrojanDropper.Agent.ACH@4m8n0u
ZillyaTrojan.PornoAsset.Win32.2184
TrendMicroTROJ_RANSOM.BRJ
McAfee-GW-EditionGeneric.iz
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Troj/Agent-VDX
SentinelOneStatic AI – Malicious PE
GDataTrojan.Ransom.EA
JiangminTrojan/Birele.ql
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Ransom.EA.1
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.300
KingsoftWin32.Troj.Generic.a.(kcloud)
ArcabitTrojan.Ransom.EA
MicrosoftRansom:Win32/Loktrom.B
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGeneric.iz
VBA32Hoax.Birele
MalwarebytesMalware.Heuristic.1003
PandaGeneric Malware
TrendMicro-HouseCallTROJ_RANSOM.BRJ
RisingRansom.Weenloc!8.519 (TFE:5:eO2ExhvfXcV)
YandexTrojan.GenAsa!sM5aqWrajac
IkarusTrojan-Ransom.PornoAsset
MaxSecureTrojan.Malware.4454766.susgen
FortinetW32/Yakes.LS!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Ransom.EA?

Trojan.Ransom.EA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment