Ransom Trojan

Trojan-Ransom.Win32.Shade.nvp information

Malware Removal

The Trojan-Ransom.Win32.Shade.nvp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Shade.nvp virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:55288
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Installs Tor on the infected machine
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Shade.nvp?


File Info:

crc32: 4AD82ABF
md5: 52e32feb3be9042b848328b889f9b3d6
name: 52E32FEB3BE9042B848328B889F9B3D6.mlw
sha1: f9bda7fe77f7b75f01eb67290944e356d5f74ef7
sha256: 9bd45f878b944d8f78265430c53d2f7febd6f01c86cdf9ea91553e7d58621aeb
sha512: 8b27e5113843cbffb698ce91c1cd198634aa2b85cff1fa630f6c3acfb4ece4fb083f40de31fe92a18b17b5a02bc14597a98a20925c0fd59e04b3941c8503ae7b
ssdeep: 24576:gUL+exoIJRY3IYoReHCZGGNmABzqf3SOfUR4loVhVE12:z+eOIJGIYoRUGMMmf3LfBlAjEI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c). All rights reserved. Nattyware
InternalName: LegendDuncan
FileVersion: 7.4.5.2
CompanyName: Nattyware
PrivateBuild: 7.4.5.2
LegalTrademarks: (c). All rights reserved. Nattyware
ProductName: LegendDuncan
Languages: English
ProductVersion: 7.4.5.2
FileDescription: Supervisin Timesheets Tweeter
OriginalFilename: LegendDuncan.exe
Translation: 0x0406 0x04b0

Trojan-Ransom.Win32.Shade.nvp also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004b8aa51 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10507
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.5597202
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Shade.8ca9ae31
K7GWTrojan ( 004b8aa51 )
Cybereasonmalicious.b3be90
SymantecTrojan Horse
ESET-NOD32Win32/Filecoder.Shade.B
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Shade.nvp
BitDefenderTrojan.GenericKD.5597202
NANO-AntivirusTrojan.Win32.Shade.falbxc
MicroWorld-eScanTrojan.GenericKD.5597202
TencentWin32.Trojan.Shade.Swut
Ad-AwareTrojan.GenericKD.5597202
SophosMal/Generic-S
ComodoMalware@#3j3hqnzfg9q7
BitDefenderThetaGen:NN.ZexaF.34628.!u0@ai7m7YeG
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPURSNIF.SMZD2
McAfee-GW-EditionBehavesLike.Win32.Downloader.dc
FireEyeGeneric.mg.52e32feb3be9042b
EmsisoftTrojan.GenericKD.5597202 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Shade.kf
AviraHEUR/AGEN.1110226
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Azorult!ml
AegisLabTrojan.Win32.Shade.j!c
GDataTrojan.GenericKD.5597202
AhnLab-V3Trojan/Win32.Shade.C2039103
Acronissuspicious
McAfeeArtemis!52E32FEB3BE9
MAXmalware (ai score=89)
VBA32Trojan-Ransom.Shade
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_HPURSNIF.SMZD2
RisingTrojan.Generic@ML.95 (RDMK:cm/oQQWRGLGfMrxoiaemWQ)
IkarusTrojan.Win32.Filecoder
FortinetW32/Shade.NVP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Shade.HgIASOgA

How to remove Trojan-Ransom.Win32.Shade.nvp?

Trojan-Ransom.Win32.Shade.nvp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment