Ransom Trojan

Trojan.Ransom.QA removal

Malware Removal

The Trojan.Ransom.QA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.QA virus can do?

  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.QA?


File Info:

name: 905165401BA5637BF001.mlw
path: /opt/CAPEv2/storage/binaries/636d111ded429af4e44c5eb95f4b80fdc97e5e4f033348fddfc4b27915989258
crc32: 630DE0DB
md5: 905165401ba5637bf001401ebb191e45
sha1: 0b2031bef4b391438a4063f66139dfdebd38ed3f
sha256: 636d111ded429af4e44c5eb95f4b80fdc97e5e4f033348fddfc4b27915989258
sha512: 08b44004d37ea84f9d276b0a39b8ccecd11ee3015b6ef2826ca3fab807967551a4248e3bde59938db2194622274c09540df1a9cf1ced0a1edf186b677a6da801
ssdeep: 768:BiP6oMZO9Hydg/96e3rG7jPZOsvVj2RI2GCYggjr229FGSs/Jlg7yVLc:saQHydUce3rG7jBOq2CSY/LySoPk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA33013CD2EEDD0BD1228378093B4B6430CF7EA56E7EB24F9C82952C2B9219513017D6
sha3_384: dd0aa417305259e2aa573fbaf1dda716a87d4afa8c4edb0e517deccfad9a4d493b74dc2129cb72021ea6738f2ff8f9ab
ep_bytes: 60be008041008dbe0090feffc7879c80
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Ransom.QA also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
MicroWorld-eScanTrojan.Ransom.QA
ClamAVWin.Ransomware.Winlock-9756646-0
FireEyeGeneric.mg.905165401ba5637b
CAT-QuickHealRansom.Weenloc.A8
ALYacTrojan.Ransom.QA
CylanceUnsafe
VIPRETrojan.Ransom.QA
SangforRansom.Win32.Loktrom.8
K7AntiVirusTrojan ( 0055e4091 )
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.01ba56
VirITTrojan.Win32.Ransomer.ASL
SymantecTrojan.Winlock
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/LockScreen.AKT
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.QA
NANO-AntivirusTrojan.Win32.Winlock.bbukms
AvastWin32:Loktrom-Q [Trj]
Ad-AwareTrojan.Ransom.QA
EmsisoftTrojan.Ransom.QA (B)
DrWebTrojan.Winlock.7048
ZillyaTrojan.LockScreen.Win32.2730
McAfee-GW-EditionGenericR-OOD!16213B5D3101
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Dropper.Agent
GDataTrojan.Ransom.QA
JiangminTrojan.Generic.abdwm
WebrootW32.Trojan.Gen
AviraTR/LockScreen.EO
Antiy-AVLTrojan/Generic.ASMalwS.24D
ArcabitTrojan.Ransom.QA
ZoneAlarmVHO:Trojan-Ransom.Win32.PornoAsset.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!905165401BA5
MAXmalware (ai score=88)
VBA32Trojan-Ransom.Winlock.gen
MalwarebytesMalware.Heuristic.1003
RisingRansom.Loktrom!8.B04 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/LockScreen.AKT!tr
BitDefenderThetaGen:NN.ZelphiF.34646.dmGfaups0Ooc
AVGWin32:Loktrom-Q [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Ransom.QA?

Trojan.Ransom.QA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment