Ransom Trojan

How to remove “Trojan-Ransom.Win32.Shade.oqu”?

Malware Removal

The Trojan-Ransom.Win32.Shade.oqu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Shade.oqu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Shade.oqu?


File Info:

crc32: CBD72071
md5: 7cdecc57d497812e89ce0a2e4dc5fbee
name: 7CDECC57D497812E89CE0A2E4DC5FBEE.mlw
sha1: 3c529e2533e1533cc8b89896b4f2fbbcb937bd3f
sha256: 8dd39bd2d13002c3a9dfbc9b83ae5071327fd0cd5d198648024baa18e170379f
sha512: dcfd9ecadb11005b177d905f9058a048f29ae671ed68f8bcf80f554f2a47bf71238e86d8d37c27526ff4d8c814178426f9f9764b14db4bf969009363d7e9d386
ssdeep: 24576:CXfusXbDzLy97klSK0ix4tMcPNTe+/Dz8E/RemAk:gDrDzG9YXitM5E/dAk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Shade.oqu also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 00539ed31 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.858
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacGen:Heur.Mint.Titirez.7yW@iO@HLVfi
ZillyaTrojan.Shade.Win32.809
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 655333331 )
Cybereasonmalicious.7d4978
CyrenW32/Crypt.LNNM-1580
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.GandCrab.B
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Shade.oqu
BitDefenderGen:Heur.Mint.Titirez.7yW@iO@HLVfi
NANO-AntivirusTrojan.Win32.Shade.fcsois
MicroWorld-eScanGen:Heur.Mint.Titirez.7yW@iO@HLVfi
TencentWin32.Trojan.Shade.Amda
Ad-AwareGen:Heur.Mint.Titirez.7yW@iO@HLVfi
SophosMal/Generic-R + Mal/GandCrab-D
ComodoTrojWare.Win32.Magniber.FGH@7nyazg
BitDefenderThetaGen:NN.ZexaF.34678.7yW@aO@HLVfi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_GANDCRAB.SMD4
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.7cdecc57d497812e
EmsisoftGen:Heur.Mint.Titirez.7yW@iO@HLVfi (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1103309
MicrosoftRansom:Win32/GandCrab.AS
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Heur.Mint.Titirez.7yW@iO@HLVfi
AhnLab-V3Trojan/Win32.Gandcrab.R228737
Acronissuspicious
McAfeeGenericRXFN-LN!7CDECC57D497
MAXmalware (ai score=98)
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.SMD4
RisingRansom.GandCrab!8.F355 (TFE:dGZlOgUGxlnfBYpFkw)
YandexTrojan.GenAsa!OumThLwSnKc
IkarusTrojan-Ransom.GandCrab
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/Kryptik.GXCI!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Trojan-Ransom.Win32.Shade.oqu?

Trojan-Ransom.Win32.Shade.oqu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment