Ransom Trojan

Trojan.Ransom.BKK removal tips

Malware Removal

The Trojan.Ransom.BKK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BKK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to remove evidence of file being downloaded from the Internet
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.BKK?


File Info:

crc32: 804301BB
md5: ba4b8b6da93a018a02e625fbdb49a76f
name: BA4B8B6DA93A018A02E625FBDB49A76F.mlw
sha1: 8c08b07134f69a04afae054ec16b56cf108142fb
sha256: ae39b4b2f1c8b97db54ea5ceb5a16fb5f8d3d0c6fdbfea1e292c5f5a17ec9c08
sha512: 81ef87c31e733ad401e235902f035c2fc6996ae0b1094f7d595873800321401b486a77fdb6b8ebf766d572f2a59bea4eaf9734e2ec789171bd82b7814aa9c506
ssdeep: 1536:0qhLYC5qCCywq2sq/FTQWt1CVlQm1XHd:B1xCyl2J9TPQVlN9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.BKK also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Sphinx.2
MicroWorld-eScanTrojan.Ransom.BKK
FireEyeGeneric.mg.ba4b8b6da93a018a
CAT-QuickHealRansom.Exxroute.A3
McAfeeRansomware-FMJ!BA4B8B6DA93A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005137001 )
BitDefenderTrojan.Ransom.BKK
K7GWTrojan ( 0050529f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34590.dmW@aKyFBrii
CyrenW32/Ransom.DC.gen!Eldorado
SymantecPacked.Generic.493
APEXMalicious
AvastWin32:Filecoder-AZ [Trj]
ClamAVWin.Ransomware.Spora-9525060-0
KasperskyHEUR:Trojan-Ransom.Win32.Spora.vho
AlibabaRansom:Win32/Spora.3b192345
NANO-AntivirusTrojan.Win32.Spora.elnkby
AegisLabTrojan.Win32.Generic.4!c
RisingRansom.Cerber!8.3058 (CLOUD)
Ad-AwareTrojan.Ransom.BKK
EmsisoftTrojan.Ransom.BKK (B)
ComodoTrojWare.Win32.Crypt.C@7vajd0
F-SecureHeuristic.HEUR/AGEN.1116787
BaiduWin32.Trojan.Kryptik.bjk
ZillyaTrojan.Kryptik.Win32.1325187
TrendMicroRansom_CERBER.SM37
McAfee-GW-EditionBehavesLike.Win32.Ransomware.qh
SophosMal/Generic-R + Mal/Elenoocka-E
IkarusTrojan.Dalexis
JiangminTrojan.Spora.bb
eGambitUnsafe.AI_Score_96%
AviraHEUR/AGEN.1116787
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Spora.A
ArcabitTrojan.Ransom.BKK
ZoneAlarmHEUR:Trojan-Ransom.Win32.Spora.vho
GDataTrojan.Ransom.BKK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.R299252
Acronissuspicious
VBA32BScope.TrojanPSW.Papras
ALYacTrojan.Ransom.BKK
MAXmalware (ai score=100)
MalwarebytesRansom.Cerber
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FOJV
TrendMicro-HouseCallRansom_CERBER.SM37
TencentWin32.Trojan.Cerber.Pftb
YandexTrojan.Kryptik!JlwQl8i6m9A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74649600.susgen
FortinetW32/Kryptik.GKVH!tr
AVGWin32:Filecoder-AZ [Trj]
Cybereasonmalicious.da93a0
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HxQBHB4A

How to remove Trojan.Ransom.BKK?

Trojan.Ransom.BKK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment