Ransom Trojan

Should I remove “Trojan:Win32/RoyalRansom!ic”?

Malware Removal

The Trojan:Win32/RoyalRansom!ic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RoyalRansom!ic virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/RoyalRansom!ic?


File Info:

name: C46070B5E113A7F5D9A5.mlw
path: /opt/CAPEv2/storage/binaries/595c869f8ec7eaf71fef44bad331d81bb934c886cdff99e1f013eec7acdaf8c9
crc32: CAD7F0D0
md5: c46070b5e113a7f5d9a58de14a11e430
sha1: 5007943bec2cf5310cfe8b8c49d6f55f79ad0e4c
sha256: 595c869f8ec7eaf71fef44bad331d81bb934c886cdff99e1f013eec7acdaf8c9
sha512: e77a2bbc22974f79f30f6673adaf78c8818d674532ef1cff4d61514ecb3d1aec0459d76c05595d1c650624bf25d4e4f06ee14841b5c2b1c5a20a27e4861ae818
ssdeep: 24576:R+KpPzIzkQoU6TPF8mkoSW12GR7qMA6v0Xwq8UcNV++e/i5dv9jOlRJYzyiMAIQB:Bq9LmKKe36MmYJPAvIPtHzHlh4UC4qki
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106A5BE06FF8295B2E8C3197922EB977F4D3969148734C9D38BD129BEC8211D1963F398
sha3_384: d72470774c618b13dd288ec7997511b252e6300b77f0612c16afefd1f0e919e39a9df8b56d3bfaed2a36704aab07ab00
ep_bytes: e816080000e97afeffffcccccccccccc
timestamp: 2022-11-12 20:11:21

Version Info:

0: [No Data]

Trojan:Win32/RoyalRansom!ic also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.j!c
MicroWorld-eScanGen:Variant.Ransom.BlackSuit.7
FireEyeGen:Variant.Ransom.BlackSuit.7
CAT-QuickHealRansom.Royal.S30115332
McAfeeRanom-Royal!C46070B5E113
MalwarebytesMalware.AI.4171289773
SangforRansom.Win32.Royal.V1y4
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/RoyalRansom.fc27f3af
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Filecoder.Royal.A
APEXMalicious
ClamAVWin.Ransomware.Royal-9980434-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Ransom.BlackSuit.7
NANO-AntivirusTrojan.Win32.Ransom.jttehh
AvastWin32:RansomX-gen [Ransom]
TencentMalware.Win32.Gencirc.10bdb344
EmsisoftGen:Variant.Ransom.BlackSuit.7 (B)
F-SecureTrojan.TR/Ransom.ceukp
DrWebTrojan.Encoder.37038
VIPREGen:Variant.Ransom.BlackSuit.7
TrendMicroRansom.Win32.ROYAL.SMYECJYT
SophosTroj/RoyalRan-C
IkarusTrojan-Ransom.FileCrypter
MAXmalware (ai score=100)
GDataGen:Variant.Ransom.BlackSuit.7
JiangminTrojan.Generic.hopst
WebrootW32.Ransom.Royal
GoogleDetected
AviraTR/Ransom.ceukp
VaristW32/Filecoder.FM.gen!Eldorado
Antiy-AVLTrojan/Win32.Filecoder
ArcabitTrojan.Ransom.BlackSuit.7
ViRobotTrojan.Win32.Z.Ransom.2235392.L
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftTrojan:Win32/RoyalRansom!ic
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Royal.R554821
BitDefenderThetaGen:NN.ZexaF.36744.iwW@a0fFREai
ALYacTrojan.Ransom.Filecoder
VBA32Trojan.Encoder
Cylanceunsafe
PandaTrj/GdSda.A
RisingRansom.Royal!1.E0FC (CLASSIC)
YandexTrojan.Filecoder!2qd94j0aBI0
SentinelOneStatic AI – Suspicious PE
FortinetW32/Filecoder.OMV!tr.ransom
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/RoyalRansom!ic?

Trojan:Win32/RoyalRansom!ic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment