Ransom Trojan

Should I remove “Trojan.Ransom.Phobos”?

Malware Removal

The Trojan.Ransom.Phobos is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Phobos virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Ransom.Phobos?


File Info:

crc32: 0DFC98BD
md5: de0be9bdd38f115698b04c8fc5866b6b
name: rcbvhfdg.exe
sha1: 64660276658b6064e7e8d49c25b428334a50302c
sha256: d73567b2d8f1dcf9c4db50a428b582c89c23147fdff5626248e520bd4f2ec5a5
sha512: 032cdc896c077ce05fd438e88c197a9c723a925bc72bf34dd4d5b11c5921aa639273f1b75f9223982228655b24afbdcaedd68f65b58ca066ba14911d50c0dd58
ssdeep: 1536:0c0+gIyddH/8kdszNrhRQTJ0+8jpkdszNrhRL+gIyddH/:K+fyddflYbRQTJ0+8jSYbRL+fyddf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0410 0x04b0
InternalName: Busser
FileVersion: 1.00
CompanyName: Personm
LegalTrademarks: Uldtrje
Comments: Maharao1
ProductName: Bewaile
ProductVersion: 1.00
OriginalFilename: Busser.exe

Trojan.Ransom.Phobos also known as:

MicroWorld-eScanTrojan.GenericKD.32993080
FireEyeTrojan.GenericKD.32993080
CAT-QuickHealTrojan.Vebzenpak
McAfeeRDN/Generic.grp
CylanceUnsafe
VIPRETrojan.Win32.VB
AegisLabTrojan.Win32.Vebzenpak.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32993080
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R011C0PAS20
BitDefenderThetaGen:NN.ZevbaF.34084.fm0@aGCnjxoG
TrendMicro-HouseCallTROJ_GEN.R011C0PAS20
AvastWin32:Trojan-gen
ClamAVWin.Trojan.VBGeneric-7564516-0
GDataTrojan.GenericKD.32993080
KasperskyTrojan.Win32.Vebzenpak.aas
AlibabaTrojan:Win32/Vebzenpak.30a984f3
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.32993080
EmsisoftTrojan.GenericKD.32993080 (B)
F-SecureTrojan.TR/Injector.odbec
DrWebTrojan.DownLoader32.52898
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.VBObfus.mm
SentinelOneDFI – Suspicious PE
Trapminemalicious.moderate.ml.score
SophosMal/FareitVB-X
APEXMalicious
CyrenW32/VB.QM!Eldorado
AviraTR/Injector.odbec
ArcabitTrojan.Generic.D1F76F38
ZoneAlarmTrojan.Win32.Vebzenpak.aas
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.VBKrypt.C3973312
VBA32TScope.Trojan.VB
ALYacTrojan.Ransom.Phobos
MAXmalware (ai score=85)
MalwarebytesTrojan.VBInject
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKEL
IkarusTrojan.VB.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.ECUV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.451

How to remove Trojan.Ransom.Phobos?

Trojan.Ransom.Phobos removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment