Ransom Trojan

Trojan-Ransom.Win32.Shade.ouo information

Malware Removal

The Trojan-Ransom.Win32.Shade.ouo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Shade.ouo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Trojan-Ransom.Win32.Shade.ouo?


File Info:

crc32: 5E33C760
md5: f5608997fb99d8481556c176bac3daee
name: F5608997FB99D8481556C176BAC3DAEE.mlw
sha1: 13ac84d2378071c6fba43a4e0a72a7f8e6ce1f92
sha256: 9c5208509ea82348f88f27abdde64e8dc8bf5f244c09273ef072a7fdc76bafa9
sha512: 268d6a2f99517a733502b2ca5a40e2f305a4a0c47a1ccad242d6c74bda1ef102e5d0782e37842e8449d948d4aac4f9e859274fae43b85b9de6e3bc6142e0d47c
ssdeep: 24576:NX6k1p5EMdw3Uaiy1Jz95mso3B5zr2lYPKuseMjRTpuyDsc5Iyhb8kTlZiYExn:0J1b5/iZSjRVuyD1CkniYExn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: The Financial Action Task Force
InternalName: Data Export Tool for SQL Database
FileVersion: 1.3.1.1
CompanyName: The Financial Action Task Force
ProductName: Data Export Tool for SQL Database
ProductVersion: 1.3.1.1
FileDescription: Data Export Tool for SQL Database
OriginalFilename: Data Export Tool for SQL Database
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Shade.ouo also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00538d151 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.858
CAT-QuickHealTrojan.Mauvaise.SL1
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.140372
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/starter.ali1000030
K7GWTrojan ( 00538d151 )
Cybereasonmalicious.237807
SymantecRansom.CryptXXX
ESET-NOD32Win32/Filecoder.Shade.A
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Shade.ouo
NANO-AntivirusTrojan.Win32.Shade.fhpyci
ViRobotTrojan.Win32.Agent.1690624
TencentWin32.Trojan.Shade.Ecjo
SophosMal/Generic-R + Troj/Xtbl-AW
ComodoMalware@#9qak2x98kgvu
BitDefenderThetaGen:NN.ZexaF.34688.Nr0@aGMOqohi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.f5608997fb99d848
JiangminTrojan.Shade.na
AviraHEUR/AGEN.1117373
eGambitUnsafe.AI_Score_73%
MicrosoftRansom:Win32/Troldesh.A
AegisLabTrojan.Win32.Generic.4!c
TACHYONRansom/W32.Shade.1690624
AhnLab-V3Trojan/Win32.FileCoder.C2644467
Acronissuspicious
McAfeeArtemis!F5608997FB99
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Shade
MalwarebytesMalware.AI.4162116149
PandaTrj/GdSda.A
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.Shade!5k7w5mFEjeU
IkarusTrojan-Spy.Remcos
FortinetW32/Shade.NRM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Shade.ouo?

Trojan-Ransom.Win32.Shade.ouo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment