Ransom Trojan

Trojan.Ransom.TroldeshKD.12716670 removal guide

Malware Removal

The Trojan.Ransom.TroldeshKD.12716670 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.TroldeshKD.12716670 virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
hobby10.2ch.net
hobby10.5ch.net

How to determine Trojan.Ransom.TroldeshKD.12716670?


File Info:

crc32: DF605F99
md5: fcc7531584d34755e8196236246d7b6b
name: FCC7531584D34755E8196236246D7B6B.mlw
sha1: 728b75e1ab814dc4936fe4a67c0d219cceeb45e8
sha256: cbcccaae0f2c579c46324ec995dc2582a3c4dc7f23fb917b0cf9cf220fbdcd2a
sha512: 720a2b3a8e2312678bfb43a2b366f0f17f9524e5e3d7e9224473888b9869f9d40451c6efeb5ceb7af3ba03e14100d6b45f1887813085b87385d3cb3080ad8b80
ssdeep: 1536:oFqCtIQ/OkCc0oAHYPZLcmTA+F4YzlPUotkR0wYsHeB7XM17xGIl/w1prNR1+aJ:oDAMJIl/wnrNR1+aJe1mgawzxsBub86
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Shinobi.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription: x30c6x30adx30b9x30c8 x30c9x30adx30e5x30e1x30f3x30c8
OriginalFilename: Shinobi.exe

Trojan.Ransom.TroldeshKD.12716670 also known as:

K7AntiVirusRiskware ( 0040eff71 )
ALYacTrojan.Ransom.TroldeshKD.12716670
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.584d34
SymantecTrojan.Gen.2
ESET-NOD32a variant of Generik.FOEPEWV
AvastWin32:AutoRun-BIR [Trj]
ClamAVWin.Trojan.Agent-51839
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderTrojan.Ransom.TroldeshKD.12716670
NANO-AntivirusTrojan.Win32.Gendal.ewptzq
MicroWorld-eScanTrojan.Ransom.TroldeshKD.12716670
TencentWin32.Trojan.Foreign.Ehhv
Ad-AwareTrojan.Ransom.TroldeshKD.12716670
ComodoMalware@#1zz9itf35jo2f
BitDefenderThetaGen:NN.ZemsilF.34110.fm0@amTX3yo
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.Ransom.TroldeshKD.12716670
EmsisoftTrojan.Ransom.TroldeshKD.12716670 (B)
AviraTR/Autorun.BIR.1
Antiy-AVLTrojan/Generic.ASMalwS.23CCDC9
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataTrojan.Ransom.TroldeshKD.12716670
McAfeeArtemis!FCC7531584D3
MAXmalware (ai score=97)
VBA32Trojan.MSIL.gen.a.1
IkarusTrojan.SuspectCRC
AVGWin32:AutoRun-BIR [Trj]
Paloaltogeneric.ml

How to remove Trojan.Ransom.TroldeshKD.12716670?

Trojan.Ransom.TroldeshKD.12716670 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment