Ransom Trojan

What is “Trojan-Ransom.Win32.PolyRansom.ddfe”?

Malware Removal

The Trojan-Ransom.Win32.PolyRansom.ddfe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.PolyRansom.ddfe virus can do?

  • Authenticode signature is invalid

How to determine Trojan-Ransom.Win32.PolyRansom.ddfe?


File Info:

name: 80999DE5155D73DD9CC7.mlw
path: /opt/CAPEv2/storage/binaries/2acadf2338c928cbf472172d17852f1030ced925c6ed876fa359a41a113a3675
crc32: B6386ACD
md5: 80999de5155d73dd9cc754f74a3aca2b
sha1: c5dfdaab612176ea51fffeb349f71d4237da5c28
sha256: 2acadf2338c928cbf472172d17852f1030ced925c6ed876fa359a41a113a3675
sha512: 3b46821926b05d80f307b6ae2ecfa2e7f575d1fec533787d9919d7034fcd303a18187b5ddc89c6a690026168b7e19aa0cd03ee65fcd3ec28184639e5ad17b9c3
ssdeep: 768:/zK0DYZYFDuvFatlnZA8aTsNL7eLYRN97eZydalfuV3lVwwQY/k:/zlYKF1uHSuLoN97eOaFufVwt6k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11003E809BBEE416AD07BEFF97CFCA65988F6E7621005F56F5440020B6D42E61CB0363A
sha3_384: 6decbb59849201738a23031fb1a9b8f2700cd0f4d9e93d2dd37338609c22c2734e1c7904728e47ec3a6e09b787fd3ca1
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-26 13:33:47

Version Info:

Translation: 0x0000 0x04b0
Comments: CmRccService
FileDescription: CmRccService
FileVersion: 5.1.1.2
InternalName: p8nmA8p9hhetW
LegalCopyright:
OriginalFilename: p8nmA8p9hhetW
ProductName: CmRccService
ProductVersion: 5.1.1.2
Assembly Version: 5.1.1.2

Trojan-Ransom.Win32.PolyRansom.ddfe also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.23258
FireEyeGeneric.mg.80999de5155d73dd
ALYacIL:Trojan.MSILZilla.23258
CylanceUnsafe
VIPREIL:Trojan.MSILZilla.23258
K7AntiVirusTrojan ( 005955001 )
BitDefenderIL:Trojan.MSILZilla.23258
K7GWTrojan ( 005955001 )
Cybereasonmalicious.b61217
ArcabitIL:Trojan.MSILZilla.D5ADA
BitDefenderThetaGen:NN.ZemsilF.34726.cm0@aevGKCl
CyrenW32/MSIL_Agent.DHY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.VIF
APEXMalicious
ClamAVWin.Packed.Msilzilla-9953300-0
KasperskyTrojan-Ransom.Win32.PolyRansom.ddfe
CynetMalicious (score: 99)
Ad-AwareIL:Trojan.MSILZilla.23258
EmsisoftIL:Trojan.MSILZilla.23258 (B)
DrWebTrojan.PackedNET.1575
McAfee-GW-EditionGenericRXUK-YY!80999DE5155D
Trapminemalicious.high.ml.score
SophosMal/DownLdr-FL
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1235639
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataIL:Trojan.MSILZilla.23258
GoogleDetected
AhnLab-V3Trojan/Win.Mardom.C5109384
Acronissuspicious
McAfeeGenericRXUK-YB!80999DE5155D
VBA32OScope.Trojan.MSIL.Basic.8
MalwarebytesTrojan.Crypt
TencentTrojan-Ransom.MSIL.PolyRansom.16000547
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.VIF!tr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]

How to remove Trojan-Ransom.Win32.PolyRansom.ddfe?

Trojan-Ransom.Win32.PolyRansom.ddfe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment