Ransom Trojan

Trojan.Ransom.Ouroboros malicious file

Malware Removal

The Trojan.Ransom.Ouroboros is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Ouroboros virus can do?

  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.Ouroboros?


File Info:

crc32: B1D196E3
md5: 97f129ed757c6b095b87b5a58f695698
name: 97F129ED757C6B095B87B5A58F695698.mlw
sha1: a1d20b051415abb1ca618416e8ace9c74531da40
sha256: 350ddf06306b557d376a93a721f065b66610642da1bbff4809fefcb40ba839dc
sha512: 48d0214d93eacd68aa8aaa438ee19facd6214595c579af75ecf3076697bd8a2f019c9ab76ac2b8fdeff331206b49046cef71580a96c2a7728a8a0e4611e7ce04
ssdeep: 24576:uAHnh+eWsN3skA4RV1Hom2KXMmHaQ5jfzhuX5:Zh+ZkldoPK8YaQ5pY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan.Ransom.Ouroboros also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f65341 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24576
CynetMalicious (score: 100)
CAT-QuickHealRansom.Autoit.CryptoWire.A
ALYacTrojan.Ransom.Ouroboros
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Ouroboros.ali1020019
K7GWTrojan ( 004f65341 )
Cybereasonmalicious.d757c6
CyrenW32/AutoIt.NU.gen!Eldorado
SymantecRansom.Cryptolocker
ESET-NOD32Win32/Filecoder.NHN
APEXMalicious
AvastAutoIt:Ransom-K [Trj]
KasperskyTrojan-Ransom.Script.Agent.f
BitDefenderTrojan.GenericKD.42832256
NANO-AntivirusTrojan.Win32.Ransom.herhdw
MicroWorld-eScanTrojan.GenericKD.42832256
TencentScript.Trojan.Agent.Hwwf
Ad-AwareTrojan.GenericKD.42832256
ComodoMalware@#25mk0l5vtn5xj
BitDefenderThetaAI:Packer.C658345116
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Cryptoit-1
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.ch
FireEyeTrojan.GenericKD.42832256
EmsisoftTrojan.GenericKD.42832256 (B)
WebrootW32.Trojan.Agent.Gen
AviraHEUR/AGEN.1100014
eGambitUnsafe.AI_Score_94%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/CryptoWire!MSR
AegisLabHacktool.Win32.Gamehack.3!e
GDataTrojan.GenericKD.42832256
McAfeeArtemis!97F129ED757C
MAXmalware (ai score=100)
VBA32TrojanRansom.Script
MalwarebytesRansom.FileCryptor
PandaTrj/CI.A
TrendMicro-HouseCallMal_Cryptoit-1
RisingRansom.CryptoWire/Autoit!1.C3A2 (CLASSIC)
IkarusTrojan-Ransom.Ouroboros
MaxSecureTrojan.Malware.73662528.susgen
FortinetAutoIt/Ouroboros.A!tr.ransom
AVGAutoIt:Ransom-K [Trj]
Paloaltogeneric.ml

How to remove Trojan.Ransom.Ouroboros?

Trojan.Ransom.Ouroboros removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment