Ransom Trojan

Should I remove “Trojan-Ransom.Win32.Instructions.vi”?

Malware Removal

The Trojan-Ransom.Win32.Instructions.vi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Instructions.vi virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Attempts to execute a binary from a dead or sinkholed URL
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Instructions.vi?


File Info:

crc32: E69952D5
md5: 4423fc145251438346493e2b8eca6c25
name: 4423FC145251438346493E2B8ECA6C25.mlw
sha1: e71a9e8ec4ffb99bd6608d28893bd9985147538d
sha256: 3255578ca08da63476a0dd976cbf6ead7a1de5f2f108590ca3eab8153579c5b0
sha512: 20f9e5e099054e3dbf9fadb78c0796bb114b07bd7c53a7e386d15f64c3cb58dfd3c4b0eb572a3579ead3472ee26eacf2e7d741ee70d5ea8e26922fa37e4262a4
ssdeep: 1536:P7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfkwaDpDOK:j7DhdC6kzWypvaQ0FxyNTBfkp3
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Instructions.vi also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052419b1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.ec4ffb
CyrenW32/Trojan.EKOZ-8825
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Ransom.Win32.Instructions.vi
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.4423fc1452514383
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.2B9E7F9
MicrosoftTrojan:Win32/Wacatac.B!ml
AegisLabTrojan.Win32.Encoder.trrL
ZoneAlarmTrojan-Ransom.Win32.Instructions.vi
TACHYONDownloader/W32.Encat.94720
McAfeeArtemis!4423FC145251
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazqzE8DuPX1XU8Rbv+qvS5Pk)
IkarusTrojan.BAT.KillAV
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Instructions.vi?

Trojan-Ransom.Win32.Instructions.vi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment