Ransom Trojan

How to remove “Trojan-Ransom.Win32.Shade.mzb”?

Malware Removal

The Trojan-Ransom.Win32.Shade.mzb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Shade.mzb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • A potential decoy document was displayed to the user
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Shade.mzb?


File Info:

crc32: 71074953
md5: b254c18d227391401ef8f36051761c53
name: B254C18D227391401EF8F36051761C53.mlw
sha1: 413e9c98b45afd2c2e2e0b54cf1e5089c9954f66
sha256: db3b70acd33d8089ee6071661736daa516a6a0073a86d2517c5db180709f2e72
sha512: 4fd9e70cfeef7e45e751e5da7e74123996c7742ffa27ebd9d3e511b1cdd8df69db70d7ff974c6af03885514fb0b5d28b1576a21dc5139b4004f398522e8f973a
ssdeep: 24576:5pVsm/7Z1awrAmWQotb2sFyOgoazp1zmUfLE4IEZKfiq:Vs9bHVUYGZJq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2016 All rights reserved. Jetico
InternalName: OverloadingPrescribed
FileVersion: 6.9.3.987
CompanyName: Jetico
LegalTrademarks: Copyright xa9 2016 All rights reserved. Jetico
Comments: Richest Dish Itx2019s Envirnment Emailed Technologies
ProductName: OverloadingPrescribed
Languages: English
ProductVersion: 6.9.3.987
FileDescription: Richest Dish Itx2019s Envirnment Emailed Technologies
OriginalFilename: OverloadingPrescribed.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Shade.mzb also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004b8aa51 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10355
McAfeeRansom-O.f
CylanceUnsafe
ZillyaTrojan.Shade.Win32.477
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Shade.2ebb37af
K7GWTrojan ( 004b8aa51 )
Cybereasonmalicious.d22739
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Shade.B
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyTrojan-Ransom.Win32.Shade.mzb
BitDefenderTrojan.GenericKD.31773656
NANO-AntivirusTrojan.Win32.Shade.eormiw
MicroWorld-eScanTrojan.GenericKD.31773656
TencentMalware.Win32.Gencirc.10bbba77
Ad-AwareTrojan.GenericKD.31773656
SophosML/PE-A
ComodoMalware@#26ar6t50zr36s
BitDefenderThetaGen:NN.ZexaF.34678.xr0@auhxWpmi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPSHED.F117E8
McAfee-GW-EditionRansom-O.f
FireEyeGeneric.mg.b254c18d22739140
EmsisoftTrojan.GenericKD.31773656 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Shade.ga
WebrootW32.Gen.BT
eGambitGeneric.Malware
MicrosoftRansom:Win32/Troldesh.A
ArcabitTrojan.Generic.D1E4D3D8
AegisLabTrojan.Multi.Generic.4!c
GDataTrojan.GenericKD.31773656
TACHYONRansom/W32.Shade.1437696
VBA32Trojan-Ransom.Shade
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CRYPSHED.F117E8
RisingRansom.Shade!8.12CC (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/Generic.AP.D048B!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Shade.HwkAEpsA

How to remove Trojan-Ransom.Win32.Shade.mzb?

Trojan-Ransom.Win32.Shade.mzb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment