Categories: RansomTrojan

Trojan-Ransom.Win32.Shade.ouo information

The Trojan-Ransom.Win32.Shade.ouo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Shade.ouo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Trojan-Ransom.Win32.Shade.ouo?


File Info:

crc32: 5E33C760md5: f5608997fb99d8481556c176bac3daeename: F5608997FB99D8481556C176BAC3DAEE.mlwsha1: 13ac84d2378071c6fba43a4e0a72a7f8e6ce1f92sha256: 9c5208509ea82348f88f27abdde64e8dc8bf5f244c09273ef072a7fdc76bafa9sha512: 268d6a2f99517a733502b2ca5a40e2f305a4a0c47a1ccad242d6c74bda1ef102e5d0782e37842e8449d948d4aac4f9e859274fae43b85b9de6e3bc6142e0d47cssdeep: 24576:NX6k1p5EMdw3Uaiy1Jz95mso3B5zr2lYPKuseMjRTpuyDsc5Iyhb8kTlZiYExn:0J1b5/iZSjRVuyD1CkniYExntype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: The Financial Action Task ForceInternalName: Data Export Tool for SQL DatabaseFileVersion: 1.3.1.1CompanyName: The Financial Action Task ForceProductName: Data Export Tool for SQL DatabaseProductVersion: 1.3.1.1FileDescription: Data Export Tool for SQL DatabaseOriginalFilename: Data Export Tool for SQL DatabaseTranslation: 0x0409 0x04b0

Trojan-Ransom.Win32.Shade.ouo also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Trojan ( 00538d151 )
Elastic malicious (high confidence)
DrWeb Trojan.Encoder.858
CAT-QuickHeal Trojan.Mauvaise.SL1
Cylance Unsafe
Zillya Trojan.GenericKD.Win32.140372
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Trojan:Win32/starter.ali1000030
K7GW Trojan ( 00538d151 )
Cybereason malicious.237807
Symantec Ransom.CryptXXX
ESET-NOD32 Win32/Filecoder.Shade.A
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 100)
Kaspersky Trojan-Ransom.Win32.Shade.ouo
NANO-Antivirus Trojan.Win32.Shade.fhpyci
ViRobot Trojan.Win32.Agent.1690624
Tencent Win32.Trojan.Shade.Ecjo
Sophos Mal/Generic-R + Troj/Xtbl-AW
Comodo Malware@#9qak2x98kgvu
BitDefenderTheta Gen:NN.ZexaF.34688.Nr0@aGMOqohi
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
FireEye Generic.mg.f5608997fb99d848
Jiangmin Trojan.Shade.na
Avira HEUR/AGEN.1117373
eGambit Unsafe.AI_Score_73%
Microsoft Ransom:Win32/Troldesh.A
AegisLab Trojan.Win32.Generic.4!c
TACHYON Ransom/W32.Shade.1690624
AhnLab-V3 Trojan/Win32.FileCoder.C2644467
Acronis suspicious
McAfee Artemis!F5608997FB99
MAX malware (ai score=100)
VBA32 BScope.TrojanRansom.Shade
Malwarebytes Malware.AI.4162116149
Panda Trj/GdSda.A
Rising Ransom.FileCryptor!8.1A7 (CLOUD)
Yandex Trojan.Shade!5k7w5mFEjeU
Ikarus Trojan-Spy.Remcos
Fortinet W32/Shade.NRM!tr
AVG Win32:Malware-gen
Paloalto generic.ml

How to remove Trojan-Ransom.Win32.Shade.ouo?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Adware.BrowseFox.305 removal

The Adware.BrowseFox.305 is considered dangerous by lots of security experts. When this infection is active,…

28 mins ago

Win32/AutoRun.VB.AUW (file analysis)

The Win32/AutoRun.VB.AUW is considered dangerous by lots of security experts. When this infection is active,…

43 mins ago

Trojan:Win64/Metasploit!pz removal guide

The Trojan:Win64/Metasploit!pz is considered dangerous by lots of security experts. When this infection is active,…

43 mins ago

What is “Win32/Agent_AGen.BLW”?

The Win32/Agent_AGen.BLW is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Backdoor:MSIL/WebShell.GMF!MTB removal instruction

The Backdoor:MSIL/WebShell.GMF!MTB is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Mikey.163204 removal instruction

The Mikey.163204 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago