Ransom Trojan

Should I remove “UDS:Trojan-Ransom.Win32.Encoder.oof”?

Malware Removal

The UDS:Trojan-Ransom.Win32.Encoder.oof is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Ransom.Win32.Encoder.oof virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Created a process from a suspicious location

How to determine UDS:Trojan-Ransom.Win32.Encoder.oof?


File Info:

name: E2660418E7C51AF4E015.mlw
path: /opt/CAPEv2/storage/binaries/d05048f511384934aec49d1423e00ac9dfcd184c899bc88712de0dca6a136191
crc32: C863D865
md5: e2660418e7c51af4e015e7584cda9d07
sha1: a28883ea73293ff11a9a0d6a5e8c8415f884fea6
sha256: d05048f511384934aec49d1423e00ac9dfcd184c899bc88712de0dca6a136191
sha512: 2cb110c0138edc73bf5ccf4ea6526d4134645b80eb35fd0df35ccaff883b36ffd3406aaab04b12d096560a0f2aca55475096485ec6ab776a40eb6213d2a11a2c
ssdeep: 12288:F7RTEyCvovcJcVE6CLn7uAmTdRnXWfBSc:F7RwHAq3aAWXW1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FD42398AAC2C5A6F9436871D8D2FAF384396E40DD9584C37F69BF3D383DC568903189
sha3_384: 1e1b88c0d91ddea8435f764215e9b267339b2fb2dc22e5671c5692565d18c4a243de6f6e2d282274941e1ed5e18fdb24
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-07-25 00:55:47

Version Info:

FileDescription: LmsD.tro
FileVersion: 7.0.0.0
LegalCopyright:
Translation: 0x0409 0x0000

UDS:Trojan-Ransom.Win32.Encoder.oof also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.846
FireEyeGeneric.mg.e2660418e7c51af4
McAfeeArtemis!E2660418E7C5
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderGen:Variant.Doina.846
K7GWTrojan ( 0051ed981 )
K7AntiVirusTrojan ( 0051ed981 )
ArcabitTrojan.Doina.846
SymantecTrojan.Dropper
ESET-NOD32NSIS/TrojanDropper.Agent.CQ
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-Ransom.Win32.Encoder.oof
Ad-AwareGen:Variant.Doina.846
EmsisoftGen:Variant.Doina.846 (B)
DrWebTrojan.MulDrop15.62138
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.jc
SophosGeneric ML PUA (PUA)
eGambitUnsafe.AI_Score_92%
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.2457464
GDataGen:Variant.Doina.846
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.846
VBA32Win32.Malware.Dropper.Heur
MalwarebytesTrojan.Agent
YandexTrojan.GenAsa!hxwuLkotvog
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.CQ!tr
AVGBV:Malware-gen
AvastBV:Malware-gen

How to remove UDS:Trojan-Ransom.Win32.Encoder.oof?

UDS:Trojan-Ransom.Win32.Encoder.oof removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment