Ransom Trojan

About “Trojan-Ransom.Win32.Instructions” infection

Malware Removal

The Trojan-Ransom.Win32.Instructions is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Instructions virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

Related domains:

ducvit.net
tuanhoho.org
thanhlow.th
hazesi.net
kiencve.net
toandang.org
bacth0san.org
n0beer.net
longtran.th
chalizer.au
wh0ami.th
dumpmy.si
bacth0san.chickenkiller.wazuh-staging.com

How to determine Trojan-Ransom.Win32.Instructions?


File Info:

crc32: 25D5D931
md5: e0cb0ba1518a438a3c243f63d93b7fbd
name: E0CB0BA1518A438A3C243F63D93B7FBD.mlw
sha1: 79777b4f0735d20e3e83b12f7c536cc39d8ed7d3
sha256: 34c068bcf39488069915770fb82b3343ad9bf1725ef10d8d7e65588cedc98bda
sha512: 9a544c69a2dc09b9ef2f79f9b69fbcae646d3860e011637c1ebcfac8d3c9797e2b42b2954e1deac4fde13b421f8fa6d404051bc5fb60a8fb68feab9080ee83e2
ssdeep: 12288:27BAJoJjd5WfHYDCdC0mztMs4yYBt1LxT8nOUM/5NALYqs3B8Ji:hJob4Y+M0mCs4yYBthd/5NKsB8
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Instructions also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.213
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37245546
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Instructions.3092d619
Cybereasonmalicious.f0735d
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Instructions.gen
BitDefenderTrojan.GenericKD.37245546
MicroWorld-eScanTrojan.GenericKD.37245546
Ad-AwareTrojan.GenericKD.37245546
SophosGeneric PUA OM (PUA)
BitDefenderThetaGen:NN.ZexaF.34796.IuW@amEqrSei
McAfee-GW-EditionBehavesLike.Win32.Worm.hh
FireEyeGeneric.mg.e0cb0ba1518a438a
EmsisoftTrojan.GenericKD.37245546 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Instructions
AviraTR/Redcap.qzqab
MicrosoftTrojan:Win32/Tnega!MSR
ArcabitTrojan.Generic.D238526A
GDataTrojan.GenericKD.37245546
AhnLab-V3Trojan/Win.Generic.C4556625
McAfeeArtemis!E0CB0BA1518A
MAXmalware (ai score=81)
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
RisingTrojan.Generic@ML.80 (RDMK:vOTEiHKDS3erRVzqU3Jwew)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Qihoo-360Win32/Heur.Generic.HykCn74A

How to remove Trojan-Ransom.Win32.Instructions?

Trojan-Ransom.Win32.Instructions removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment