Ransom Trojan

Trojan-Ransom.Win32.Shade.yn information

Malware Removal

The Trojan-Ransom.Win32.Shade.yn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Shade.yn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Reads data out of its own binary image
  • A process created a hidden window
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

Related domains:

dvylkiow.pl
tvayxprdycjaceia.info
cyrqpmukywgyh.pl
ghlgwbnxavkvhw.su
iscoyexclohjqwmwf.work
jamvhaypjf.work
awfcoqqsmlfsda.xyz
ensxbepr.click

How to determine Trojan-Ransom.Win32.Shade.yn?


File Info:

crc32: 3213BA3D
md5: d35d938cccbccb5b84a19d2271c97ae7
name: D35D938CCCBCCB5B84A19D2271C97AE7.mlw
sha1: 0276b60e586452c60199bd605f45248dc5e7649c
sha256: a5eeba06ab0d94894a423582d05d0e10728dca46d618503e5ebaa5b911c9be17
sha512: 88529244f3cd18e277c3bab5be6c7bc9d6bc9a6e7a22b115513312504ab9171f39596eeb070884cb28f28b32e2e13d445df93b08b1982a67857b0cb3231b3308
ssdeep: 6144:6qaFH+93l/MzAX9ZibpFXR28Oth23ueLmmNoRBIWj8he7OKfro:S5el/Htw74/KLDN6BvQ87OKk
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Shade.yn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e4081 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
CynetMalicious (score: 99)
CAT-QuickHealRansom.Locky.A
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Shade.a3fdad83
K7GWTrojan ( 0055e4081 )
Cybereasonmalicious.cccbcc
SymantecTrojan Horse
ESET-NOD32Win32/Filecoder.Locky.C
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Shade.yn
BitDefenderTrojan.NSIS.Androm.6
NANO-AntivirusTrojan.Dos.Code.egouyv
ViRobotTrojan.Win32.S.Locky.276622
MicroWorld-eScanTrojan.NSIS.Androm.6
TencentWin32.Trojan.Filecoder.Wpjh
SophosMal/Generic-R + Troj/Ransom-DQP
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_LOCKY.TUEDLO
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGeneric.mg.d35d938cccbccb5b
EmsisoftTrojan.NSIS.Androm.6 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1118010
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Locky
ArcabitTrojan.NSIS.Androm.6
AegisLabTrojan.Win32.Locky.j!c
GDataTrojan.NSIS.Androm.6
TACHYONRansom/W32.Locky.276622
AhnLab-V3Trojan/Win32.Miuref.R187783
McAfeeArtemis!D35D938CCCBC
MAXmalware (ai score=100)
VBA32Hoax.Locky
MalwarebytesMalware.AI.3991203772
PandaTrj/CI.A
TrendMicro-HouseCallRansom_LOCKY.TUEDLO
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Shade.yn?

Trojan-Ransom.Win32.Shade.yn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment