Categories: RansomTrojan

Trojan.Ransom.TroldeshKD.12716670 removal guide

The Trojan.Ransom.TroldeshKD.12716670 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.TroldeshKD.12716670 virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
hobby10.2ch.net
hobby10.5ch.net

How to determine Trojan.Ransom.TroldeshKD.12716670?


File Info:

crc32: DF605F99md5: fcc7531584d34755e8196236246d7b6bname: FCC7531584D34755E8196236246D7B6B.mlwsha1: 728b75e1ab814dc4936fe4a67c0d219cceeb45e8sha256: cbcccaae0f2c579c46324ec995dc2582a3c4dc7f23fb917b0cf9cf220fbdcd2asha512: 720a2b3a8e2312678bfb43a2b366f0f17f9524e5e3d7e9224473888b9869f9d40451c6efeb5ceb7af3ba03e14100d6b45f1887813085b87385d3cb3080ad8b80ssdeep: 1536:oFqCtIQ/OkCc0oAHYPZLcmTA+F4YzlPUotkR0wYsHeB7XM17xGIl/w1prNR1+aJ:oDAMJIl/wnrNR1+aJe1mgawzxsBub86type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0LegalCopyright: Assembly Version: 1.0.0.0InternalName: Shinobi.exeFileVersion: 1.0.0.0ProductVersion: 1.0.0.0FileDescription: x30c6x30adx30b9x30c8 x30c9x30adx30e5x30e1x30f3x30c8OriginalFilename: Shinobi.exe

Trojan.Ransom.TroldeshKD.12716670 also known as:

K7AntiVirus Riskware ( 0040eff71 )
ALYac Trojan.Ransom.TroldeshKD.12716670
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
K7GW Riskware ( 0040eff71 )
Cybereason malicious.584d34
Symantec Trojan.Gen.2
ESET-NOD32 a variant of Generik.FOEPEWV
Avast Win32:AutoRun-BIR [Trj]
ClamAV Win.Trojan.Agent-51839
Kaspersky HEUR:Trojan-Ransom.Win32.Generic
BitDefender Trojan.Ransom.TroldeshKD.12716670
NANO-Antivirus Trojan.Win32.Gendal.ewptzq
MicroWorld-eScan Trojan.Ransom.TroldeshKD.12716670
Tencent Win32.Trojan.Foreign.Ehhv
Ad-Aware Trojan.Ransom.TroldeshKD.12716670
Comodo Malware@#1zz9itf35jo2f
BitDefenderTheta Gen:NN.ZemsilF.34110.fm0@amTX3yo
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition Artemis!Trojan
FireEye Trojan.Ransom.TroldeshKD.12716670
Emsisoft Trojan.Ransom.TroldeshKD.12716670 (B)
Avira TR/Autorun.BIR.1
Antiy-AVL Trojan/Generic.ASMalwS.23CCDC9
Microsoft Backdoor:Win32/Bladabindi!ml
ZoneAlarm HEUR:Trojan-Ransom.Win32.Generic
GData Trojan.Ransom.TroldeshKD.12716670
McAfee Artemis!FCC7531584D3
MAX malware (ai score=97)
VBA32 Trojan.MSIL.gen.a.1
Ikarus Trojan.SuspectCRC
AVG Win32:AutoRun-BIR [Trj]
Paloalto generic.ml

How to remove Trojan.Ransom.TroldeshKD.12716670?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.1560801952 malicious file

The Malware.AI.1560801952 is considered dangerous by lots of security experts. When this infection is active,…

28 mins ago

Malware.AI.3778280684 removal tips

The Malware.AI.3778280684 is considered dangerous by lots of security experts. When this infection is active,…

33 mins ago

Should I remove “Jalapeno.777”?

The Jalapeno.777 is considered dangerous by lots of security experts. When this infection is active,…

33 mins ago

MSIL/Kryptik.ALMH (file analysis)

The MSIL/Kryptik.ALMH is considered dangerous by lots of security experts. When this infection is active,…

39 mins ago

Should I remove “Trojan.Win32.Agent.xbmkrx”?

The Trojan.Win32.Agent.xbmkrx is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Tedy.179306 removal guide

The Tedy.179306 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago