Ransom Trojan

Trojan-Ransom.Win32.Darkside.k removal guide

Malware Removal

The Trojan-Ransom.Win32.Darkside.k is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Darkside.k virus can do?

  • At least one process apparently crashed during execution
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • A script or command line contains a long continuous string indicative of obfuscation
  • Harvests cookies for information gathering
  • Attempts to execute suspicious powershell command arguments
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Darkside.k?


File Info:

name: AC385C2DE87508379EDA.mlw
path: /opt/CAPEv2/storage/binaries/858e3159cb81705e095ef58c72138d36973de9b4dedec01a900cb0853dc9b892
crc32: 3A84038A
md5: ac385c2de87508379eda2e2ea191013b
sha1: b1784fe222f8f62624931b56cbc5eab580311f1f
sha256: 858e3159cb81705e095ef58c72138d36973de9b4dedec01a900cb0853dc9b892
sha512: 850ac04e950b6ba1738b384c0fbb6718d9bbd48931bb5dc63a2c748e70e8aea2425d94c9fe66e668777c79946db37c23113b61c6d8230d21381d7a26692631bf
ssdeep: 768:9jjV7Iax7F3jS4/S9F+YeYf+tB1tJq5c2yGHMwY23W5:vx7Fu4/iF5eTtJq1sLZ5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B433B7C33D1D1BBEE610AB55E4837B293886F7239665C0683682E24A2F0D27CB67517
sha3_384: 0fd7db9b4b2e84e164d9946e9646e8c8f74cadbe09bb9b691ef6b2f59f8ac968296eb275adca9fab45fb63b4e1ca63d4
ep_bytes: e8a3fcffff6a00e800000000ff250890
timestamp: 2020-12-15 22:26:41

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Darkside.k also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Packed.DarkSide-9262656-0
CAT-QuickHealRansom.DarkSide.S20662304
ALYacGen:Heur.Ransom.RTH.1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderGen:Heur.Ransom.RTH.1
CyrenW32/Filecoder.AP.gen!Eldorado
SymantecRansom.Darkside
ESET-NOD32a variant of Win32/Filecoder.DarkSide.A
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Darkside.k
NANO-AntivirusTrojan.Win32.Encoder.ieuyrw
MicroWorld-eScanGen:Heur.Ransom.RTH.1
RisingTrojan.Filecoder!8.68 (C64:YzY0OshLazOYOLf/)
Ad-AwareGen:Heur.Ransom.RTH.1
EmsisoftGen:Heur.Ransom.RTH.1 (B)
DrWebTrojan.Encoder.33337
ZillyaTrojan.Filecoder.Win32.17246
TrendMicroRansom.Win32.DARKSIDE.SMYAAK-B
McAfee-GW-EditionGenericRXNK-MC!AC385C2DE875
FireEyeGeneric.mg.ac385c2de8750837
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Ransom.RTH.1
JiangminTrojan-Ransom.Darkside.e
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.3109A59
ArcabitTrojan.Ransom.RTH.1
MicrosoftRansom:Win32/DarkSide!MSR
AhnLab-V3Trojan/Win.Ransom.R419377
McAfeeGenericRXNK-MC!AC385C2DE875
TACHYONRansom/W32.DarkSide.60416.C
VBA32BScope.Trojan.Diple
MalwarebytesRansom.DarkSide
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.DARKSIDE.SMYAAK-B
YandexTrojan.Gen!bVUlzES6GY4
IkarusTrojan-Ransom.DarkSide
eGambitTrojan.Generic
FortinetW32/Filecoder.ODE!tr.ransom
BitDefenderThetaAI:Packer.F99F977C1E
AVGWin32:DarkSide-C [Ransom]
Cybereasonmalicious.de8750
AvastWin32:DarkSide-C [Ransom]
MaxSecureTrojan.Malware.117563960.susgen

How to remove Trojan-Ransom.Win32.Darkside.k?

Trojan-Ransom.Win32.Darkside.k removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment