Ransom Trojan

Trojan-Ransom.Win32.Shade.owy (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Shade.owy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Shade.owy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Trojan-Ransom.Win32.Shade.owy?


File Info:

crc32: E1990587
md5: a236e728ba2da95231779bbc229dbfbb
name: A236E728BA2DA95231779BBC229DBFBB.mlw
sha1: 42231553c3a24d506a53eb25bec2d87a2f66d8f8
sha256: a77ef1f09bcafb2fa3bd84719c0fbbb92c8ddb57f1637e8e9c7abe65881b5113
sha512: f2e9dc7e712c42672ce7f0a6c4998fd4627e8777d09a26ffd26b8845f370064452a842afe9cf458efecc6246314d85a8e267396cf449e215fa1534916a0768d9
ssdeep: 24576:esASMkV8AsibSHNcii8daE0wzyHH/mg3IGiQ/5+hLPWs3:PV8vHNLdaFwz+mg3IGiQR+hLPWs
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9WeWork. All rights reserved.
InternalName: Ambiguous
FileVersion: 6.6.45.3
CompanyName: WeWork
PrivateBuild: 6.6.45.3
LegalTrademarks: Copyright xa9WeWork. All rights reserved.
Comments: Zipi Home Outwards Famous
ProductName: Ambiguous
ProductVersion: 6.6.45.3
FileDescription: Zipi Home Outwards Famous
OriginalFilename: Ambiguous
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Shade.owy also known as:

K7AntiVirusTrojan ( 004b8aa51 )
DrWebTrojan.Encoder.858
CynetMalicious (score: 100)
ALYacGen:Variant.Brresmon.126
CylanceUnsafe
ZillyaTrojan.Shade.Win32.823
SangforTrojan.Win32.GenericKD.31285314
AlibabaRansom:Win32/Shade.0828767e
K7GWTrojan ( 004b8aa51 )
Cybereasonmalicious.8ba2da
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Shade.B
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Shade.owy
BitDefenderGen:Variant.Brresmon.126
NANO-AntivirusTrojan.Win32.Shade.fjeycq
MicroWorld-eScanGen:Variant.Brresmon.126
TencentWin32.Trojan.Shade.Ljjq
Ad-AwareGen:Variant.Brresmon.126
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34722.knKfamnl@pli
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
FireEyeGen:Variant.Brresmon.126
EmsisoftGen:Variant.Brresmon.126 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Shade.no
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1109748
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.2893623
MicrosoftRansom:Win32/Troldesh!rfn
ArcabitTrojan.Brresmon.126
AegisLabTrojan.Win32.Shade.4!c
GDataGen:Variant.Brresmon.126
AhnLab-V3Malware/Win32.Generic.C2765187
McAfeeArtemis!A236E728BA2D
MAXmalware (ai score=99)
VBA32TrojanRansom.Shade
PandaTrj/CI.A
YandexTrojan.Shade!Thw17njiQ9k
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Kryptik.GKNI!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Shade.owy?

Trojan-Ransom.Win32.Shade.owy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment