Trojan

Trojan.Generic.KD.300418 removal guide

Malware Removal

The Trojan.Generic.KD.300418 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.KD.300418 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Trojan.Generic.KD.300418?


File Info:

crc32: 00FA1714
md5: 1fc48a8e799e05b5ad4f24cab11b5198
name: 1FC48A8E799E05B5AD4F24CAB11B5198.mlw
sha1: 1154dbcef8342f61c2c440b585531a235fed1f33
sha256: 2b2c595d9309fefae84082d711f5b7af6369030377fd9864bfbb06e08dc2196c
sha512: 0452c82312b30d228d20cbac9728c7e231b1b5af91038d365e785cf8fed34d991f953636054d9c1c11fe376736e68899fa4694373ff3fa82a60c54c456eaf9b9
ssdeep: 1536:ymTulkHB1rsbKSp5MS6IqPElDr1HiZVtH2PKRHpNFyLqD1nouy83l:BY+nrsbKSpbh/lDrFiZVtWi7nyuDtou
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Scala Hemingway Sandburg Armonk Dewitt
InternalName: kaftn
FileVersion: 5.06.0006
CompanyName: Johannes Signora Belgium Arturo Cicero
Comments: Liechtenstein Uniroyal Celt Darius Triangulum
ProductName: Mirfak Richter
ProductVersion: 5.06.0006
FileDescription: Schroeder Bolshevist Geigy Fairfax
OriginalFilename: kaftn.exe

Trojan.Generic.KD.300418 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0001140e1 )
LionicTrojan.Win32.Mbro.j!c
DrWebTrojan.MulDrop2.50041
CynetMalicious (score: 100)
ALYacTrojan.Generic.KD.300418
CylanceUnsafe
ZillyaTrojan.Mbro.Win32.13
AlibabaRansom:Win32/Timer.d9f0827a
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.e799e0
CyrenW32/Ransom.DKKE-8483
ESET-NOD32Win32/LockScreen.AGM
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Barys-6978940-0
KasperskyTrojan-Ransom.Win32.Timer.kkc
BitDefenderTrojan.Generic.KD.300418
NANO-AntivirusTrojan.Win32.MLW.cvzcz
ViRobotTrojan.Win32.A.Timer.69632.C
MicroWorld-eScanTrojan.Generic.KD.300418
TencentWin32.Trojan.Timer.mau
Ad-AwareTrojan.Generic.KD.300418
ComodoMalware@#32ov48fj8txxo
BitDefenderThetaAI:Packer.9AC3A97920
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_RANSOM.VS
FireEyeTrojan.Generic.KD.300418
EmsisoftTrojan.Generic.KD.300418 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Timer.eit
WebrootW32.Ransom.Pornorolik
AviraTR/Samca.hcywf
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.108ABB7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Vigorf.A
ArcabitTrojan.Generic.KD.D49582
GDataTrojan.Generic.KD.300418
McAfeeGeneric.gv
MAXmalware (ai score=100)
VBA32Hoax.Timer
MalwarebytesBackdoor.Bot
PandaGeneric Malware
TrendMicro-HouseCallTROJ_RANSOM.VS
YandexTrojan.LockScreen!Vs5GlKPdIEk
IkarusTrojan.Win32.Ransom
MaxSecureTrojan.Malware.119788117.susgen
FortinetW32/Mbro.RY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Generic.KD.300418?

Trojan.Generic.KD.300418 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment