Ransom Trojan

What is “Trojan.Ransom.TroldeshKD.12625962”?

Malware Removal

The Trojan.Ransom.TroldeshKD.12625962 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.TroldeshKD.12625962 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Anomalous binary characteristics

Related domains:

custom.generatione.tech

How to determine Trojan.Ransom.TroldeshKD.12625962?


File Info:

crc32: 6962EF14
md5: b5497e29878093b0e0456b5c1d5e3b8c
name: B5497E29878093B0E0456B5C1D5E3B8C.mlw
sha1: c5a07bf2327500393f43713e16c98f55ff5f7a48
sha256: 561510e90d56ffb30f2361b6c7c5e81d3f8ae6ba9bae0424fdc8a62ab768e882
sha512: b976fdb180448ca55aeb05553c191b40a3b9541be76c79ca7f3dc49ea24d146722bf734fd96bae6242df0c71642572da36d3b4b80df876b78b97e2445bbb3d5f
ssdeep: 6144:6qaFH+93lemVTMsDoLoWmUxvr9BERH+HcdK1:S5elfAsETm4sddK1
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan.Ransom.TroldeshKD.12625962 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Miuref-9861663-0
CAT-QuickHealRansom.Locky.A
ALYacTrojan.Ransom.TroldeshKD.12625962
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Shade.d708912f
K7GWTrojan ( 0055e4081 )
K7AntiVirusTrojan ( 0055e4081 )
SymantecPacked.NSISPacker!g3
ESET-NOD32NSIS/Injector.EV
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Shade.yn
BitDefenderTrojan.Ransom.TroldeshKD.12625962
NANO-AntivirusTrojan.Dos.Code.egouyv
MicroWorld-eScanTrojan.Ransom.TroldeshKD.12625962
TencentWin32.Backdoor.Netwire.Kiuy
Ad-AwareTrojan.Ransom.TroldeshKD.12625962
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_LOCKYENC.SMNS1
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.dc
FireEyeGeneric.mg.b5497e29878093b0
EmsisoftTrojan.Ransom.TroldeshKD.12625962 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1118010
MicrosoftBackdoor:Win32/NetWiredRC.C
ArcabitTrojan.Ransom.TroldeshKD.DC0A82A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.TroldeshKD.12625962
AhnLab-V3Trojan/Win32.Miuref.R187783
McAfeeArtemis!B5497E298780
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallRansom_LOCKYENC.SMNS1
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Ransom.TroldeshKD.12625962?

Trojan.Ransom.TroldeshKD.12625962 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment