Trojan

Trojan.Win32.Raas.a (file analysis)

Malware Removal

The Trojan.Win32.Raas.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Raas.a virus can do?

  • Presents an Authenticode digital signature
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Raas.a?


File Info:

crc32: 0D838918
md5: a24bdc5d9183800e47cea960d7673661
name: A24BDC5D9183800E47CEA960D7673661.mlw
sha1: 5fd244accafad44b72ccc882e9a278626920e7de
sha256: 032cd02d9cb4c40c3fbe02356b34408aebe1681d01a5a327f41179149812fa7f
sha512: f8c868644587ac780410358de727b58a58fd390ad2421f7b1fd0d5fac797f96b86b1f2eb85c17889411890ffcd981ca332151a171a55c39393a57f8bba1119c8
ssdeep: 3072:J5Of0m11lbOyaV2rKJIFCOL6pswNBhX1VpCLZhwj20QImOq5MpVmP5YUaLQZ/gp:aMH/IH6NBM+y0s5Ssdqp
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Raas.a also known as:

K7AntiVirusUnwanted-Program ( 004d53f61 )
DrWebTrojan.MulDrop6.12719
CynetMalicious (score: 100)
CAT-QuickHealRansom.Sarento.MUE.JV7
CylanceUnsafe
ZillyaTrojan.SarentoCRTD.Win32.5124
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Sarento.47e82646
K7GWUnwanted-Program ( 004d53f61 )
Cybereasonmalicious.ccafad
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NFP
APEXMalicious
AvastWin32:Sarento-A [Trj]
ClamAVWin.Ransomware.Sarento-7492109-0
KasperskyTrojan.Win32.Raas.a
NANO-AntivirusTrojan.Win32.Raas.eblmhw
TencentWin32.Init..cjlz
SophosMal/Generic-R + Troj/Ransom-BRE
ComodoMalware@#3bmqqt53cuxgk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.a24bdc5d9183800e
JiangminVariant.Symmi.di
AviraHEUR/AGEN.1137948
Antiy-AVLTrojan/Generic.ASMalwS.17C6990
KingsoftWin32.Troj.Raas.a.(kcloud)
MicrosoftRansom:Win32/Sarento.B
AegisLabTrojan.Win32.Raas.4!c
ZoneAlarmTrojan.Win32.Raas.a
GDataWin32.Trojan-Ransom.RaaS.F
AhnLab-V3Trojan/Win32.Sarento.R169806
McAfeeArtemis!A24BDC5D9183
VBA32BScope.Trojan.Raas
MalwarebytesMalware.AI.1851629019
PandaTrj/CI.A
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.GenAsa!qe4TqecDLh8
IkarusTrojan-Ransom.RaaS
AVGWin32:Sarento-A [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Raas.a?

Trojan.Win32.Raas.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment