Ransom Trojan

Trojan-Ransom.Win32.Encoder.ddp removal tips

Malware Removal

The Trojan-Ransom.Win32.Encoder.ddp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Encoder.ddp virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Attempts to modify desktop wallpaper
  • Attempts to disable Windows Defender
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Encoder.ddp?


File Info:

crc32: 453F4E61
md5: 93a4ce8aaa99ae88b7ee3d0728335141
name: 93A4CE8AAA99AE88B7EE3D0728335141.mlw
sha1: ab7cec39128701dafe168eaf65f56e4927098d5c
sha256: 627297193766ee11dbb86eb543f37a977c60c7fb8f977437a86e4b00a0d8a8e9
sha512: e8c6ec958b78a1ce43987fa76e5092652fa098b77e1f3561a499d230dcf33437fdcdae972d18a04543ac36636ecbcacdfdb1b533ee63161300f02a16ceb4b5a8
ssdeep: 12288:Whxp3lZnT9bDW43YAJmigFAwv64l1srHtqCh6AeT6wU:WJlh9bDW4IjigFPl1stqy6AeWwU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Encoder.ddp also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!e
DrWebTrojan.MulDrop8.28617
CynetMalicious (score: 100)
CylanceUnsafe
SangforRansom.Win32.Encoder.ddp
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:BAT/RenameFiles.9ce7acdf
Cybereasonmalicious.912870
SymantecTrojan.Gen.MBT
ESET-NOD32BAT/RenameFiles.C
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Renamefiles-6895528-0
KasperskyTrojan-Ransom.Win32.Encoder.ddp
NANO-AntivirusTrojan.Win32.RenameFiles.fewlny
SophosMal/Generic-S
ComodoMalware@#1le4pdh2b05wo
TrendMicroHackTool.VBS.InviBat.B
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.93a4ce8aaa99ae88
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win32.Generic.C2642519
McAfeeRDN/Ransom
MAXmalware (ai score=99)
MalwarebytesMalware.AI.4248645863
TrendMicro-HouseCallHackTool.VBS.InviBat.B
IkarusTrojan.BAT.RenameFiles
MaxSecureTrojan.Malware.300983.susgen
FortinetVBS/RenameFiles.C!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Encoder.HwYDFlsA

How to remove Trojan-Ransom.Win32.Encoder.ddp?

Trojan-Ransom.Win32.Encoder.ddp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment