Ransom Trojan

About “Trojan.Ransom.Obama.A” infection

Malware Removal

The Trojan.Ransom.Obama.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Obama.A virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

How to determine Trojan.Ransom.Obama.A?


File Info:

crc32: DEBB2564
md5: 8ee6ed5e547767c5fa300618d01834c9
name: 8EE6ED5E547767C5FA300618D01834C9.mlw
sha1: aeb7115d09d280e24a5377bbc99abd5b2769f09f
sha256: 6a97d7cf33991fc058131bb70fd1bac579f5dcb424315174cdc4e59f985a48f6
sha512: 0e9566b2a9172b48c52309aaec96727e140f450b5517e6b26f59c042c85c44b2d3fc0e890877cf8d9c6007663186a8541d3e544721cf2e663979a6f7f0d82a5e
ssdeep: 24576:WFwvcMczi2I0CHpQlDOk0Uig4LMwbQ4Mf7Pgw433naEtlG:WqXczupQbZ4v8v7PgwwnaEG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Barack Obama's Everlasting Blue Blackmail Virus
FileVersion: 1.0.0.0
Comments: Barack Obama's Everlasting Blue Blackmail Virus
ProductName: Barack Obama's Everlasting Blue Blackmail Virus
ProductVersion: 1.0.0.0
FileDescription: Barack Obama's Everlasting Blue Blackmail Virus
Translation: 0x0804 0x04b0

Trojan.Ransom.Obama.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26282
ClamAVWin.Malware.Zusy-6717397-0
ALYacTrojan.Ransom.Obama.A
MalwarebytesTrojan.MalPack.FlyStudio
ZillyaTrojan.GenericKD.Win32.157101
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Avkill.a9bc2108
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.e54776
BaiduWin32.Trojan.KillAV.f
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Disabler.NCP
APEXMalicious
AvastWin32:AutoRun-BRF [Wrm]
CynetMalicious (score: 70)
KasperskyVHO:Trojan-Ransom.Win32.CryptExe.gen
BitDefenderTrojan.Ransom.Obama.A
NANO-AntivirusTrojan.Win32.CryptExe.fhppre
ViRobotTrojan.Win32.Ransom.1642496
MicroWorld-eScanTrojan.Ransom.Obama.A
TencentMalware.Win32.Gencirc.114d46ed
Ad-AwareTrojan.Ransom.Obama.A
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34686.Zr0@aqHonLfb
McAfee-GW-EditionRansomware-GLW!8EE6ED5E5477
FireEyeGeneric.mg.8ee6ed5e547767c5
EmsisoftTrojan.Ransom.Obama.A (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/Patched.Ren
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Avkill.E
GDataTrojan.Ransom.Obama.A
AhnLab-V3Trojan/Win32.Cryptexe.C2695612
McAfeeRansomware-GLW!8EE6ED5E5477
MAXmalware (ai score=83)
PandaTrj/GdSda.A
RisingTrojan.Killav!1.9D3A (CLOUD)
YandexTrojan.Disabler!EpstWP4CPyo
IkarusTrojan.Win32.Disabler
FortinetW32/CoinMiner.65CA!tr
AVGWin32:AutoRun-BRF [Wrm]
Paloaltogeneric.ml

How to remove Trojan.Ransom.Obama.A?

Trojan.Ransom.Obama.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment