Ransom Trojan

About “Trojan.Ransom.CryptXXXKD.12606636” infection

Malware Removal

The Trojan.Ransom.CryptXXXKD.12606636 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.CryptXXXKD.12606636 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ransom.CryptXXXKD.12606636?


File Info:

crc32: 800DB14C
md5: aec6303c0a50a44c61581c53c0bd92d9
name: AEC6303C0A50A44C61581C53C0BD92D9.mlw
sha1: f7e85f4dced14cdb6155fec86e846ad3e903b2b6
sha256: 003e685ce9517f309b9c2469b7e6e0cd1c8bdfdf36b328ed0c4d52289769f9fd
sha512: bb71c9ddd4914bda6d689f595983c497df350b13567415dc7418ec8e23eb2d44c07fb361e6221b322c3fb4d4f77b53176acc0fec672a7e03cd9a112b49b2940e
ssdeep: 6144:YRwRsi2gBJDx+QQKl7enV5SOZdzNqYTtcny6y:5920V+jKl16Ttay
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013 Nero AG and its licensors
InternalName: NeroDisc
FileVersion: 15,0,25,0
CompanyName: Nero AG
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: NeroDiscMergeWrongDisc
SpecialBuild: 15,0,25,0
ProductVersion: 15,0,25,0
FileDescription: NeroDiscMergeWrongDisc Application
OriginalFilename: NeroDiscMergeWrongDisc.exe
Translation: 0x0409 0x04e4

Trojan.Ransom.CryptXXXKD.12606636 also known as:

K7AntiVirusTrojan ( 0051e08e1 )
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 99)
CAT-QuickHealDownldr.Freepds.MUE.ZZ5
ALYacTrojan.Ransom.CryptXXXKD.12606636
CylanceUnsafe
ZillyaTrojan.CryptXXX.Win32.770
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Tovicrypt.c9b1a462
K7GWTrojan ( 0051e08e1 )
Cybereasonmalicious.c0a50a
CyrenW32/S-2af32512!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.BHOV
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.CryptXXXKD.12606636
NANO-AntivirusTrojan.Win32.CryptXXX.evdmut
MicroWorld-eScanTrojan.Ransom.CryptXXXKD.12606636
TencentWin32.Trojan.Cryptxxx.Lrik
Ad-AwareTrojan.Ransom.CryptXXXKD.12606636
SophosMal/Generic-R + Mal/Swizzor-D
ComodoMalware@#27pxtc2zk2fob
BitDefenderThetaGen:NN.ZexaF.34142.xy0@aCnTzxti
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Crypmic-1
McAfee-GW-EditionRansomware-GJA!AEC6303C0A50
FireEyeGeneric.mg.aec6303c0a50a44c
EmsisoftTrojan.Ransom.CryptXXXKD.12606636 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1110705
Antiy-AVLTrojan/Generic.ASMalwS.22B71B0
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.Ransom.CryptXXXKD.DC05CAC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.CryptXXXKD.12606636
Acronissuspicious
McAfeeRansomware-GJA!AEC6303C0A50
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.2451378745
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_Crypmic-1
RisingTrojan.Generic@ML.95 (RDML:0iI5byIEQirWze4043ZCqw)
YandexTrojan.GenAsa!/Jktgqz9N7U
IkarusTrojan-Ransom.Tovicrypt
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Ransom.CryptXXXKD.12606636?

Trojan.Ransom.CryptXXXKD.12606636 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment