Ransom Trojan

How to remove “Trojan.Ransom.TroldeshKD.6167423”?

Malware Removal

The Trojan.Ransom.TroldeshKD.6167423 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.TroldeshKD.6167423 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.TroldeshKD.6167423?


File Info:

crc32: 39F96871
md5: 60b5000dafa3b25dad9a8e8b8a04e367
name: 60B5000DAFA3B25DAD9A8E8B8A04E367.mlw
sha1: 5b5aecad507589ed0c8a2017220394311ec1442c
sha256: 7acb2a1db28f368e3e9382c61732f00e0cb794c05a1658b7cabccad02b0c84d4
sha512: 0bbedc0c23cbc26244f5b51f355bed2c2e80c04817770d2c51b919c280b7f921e8a88bef26a7e80e22712b049632577a306167ec21bdb7a3b88d0b3ae085c9ac
ssdeep: 6144:xQiiZr2l/p4ib0U7cE8CVvXnJawHnFJxP7KbbNppBNBsY:Sx4/pjb0UwCywHFfav
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2006-2014 Intarcia Therapeutics
InternalName: Metroactive
FileVersion: 7.4.7.418
CompanyName: Intarcia Therapeutics
Comments: Cameras Pressing Cncluding Prefers Tph
ProductName: Metroactive
ProductVersion: 7.4.7.418
FileDescription: Cameras Pressing Cncluding Prefers Tph
Translation: 0x0406 0x04b0

Trojan.Ransom.TroldeshKD.6167423 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3953
CynetMalicious (score: 100)
ALYacTrojan.Ransom.TroldeshKD.6167423
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Crusis.b1bc2e97
Cybereasonmalicious.dafa3b
SymantecDownloader
ESET-NOD32Win32/Filecoder.Crysis.P
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crusis.aml
BitDefenderTrojan.Ransom.TroldeshKD.6167423
NANO-AntivirusTrojan.Win32.Encoder.euxfvr
MicroWorld-eScanTrojan.Ransom.TroldeshKD.6167423
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.Ransom.TroldeshKD.6167423
SophosMal/Generic-S
ComodoMalware@#bamevhv331ul
F-SecureHeuristic.HEUR/AGEN.1124559
BitDefenderThetaGen:NN.ZexaF.34608.vu0@ae1nndmG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SME
McAfee-GW-EditionBehavesLike.Win32.Emotet.fc
FireEyeGeneric.mg.60b5000dafa3b25d
EmsisoftTrojan.Ransom.TroldeshKD.6167423 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1124559
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Genasom
ArcabitTrojan.Ransom.TroldeshKD.D5E1B7F
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmTrojan-Ransom.Win32.Crusis.aml
GDataTrojan.Ransom.TroldeshKD.6167423
AhnLab-V3Win-Trojan/Sagecrypt.Gen
Acronissuspicious
McAfeeArtemis!60B5000DAFA3
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Crusis
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPLOCKY.SME
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.Crusis!a3QUPT4zcGU
IkarusTrojan.Win32.Filecoder
FortinetW32/Filecoder_Crysis.P!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.bb5

How to remove Trojan.Ransom.TroldeshKD.6167423?

Trojan.Ransom.TroldeshKD.6167423 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment