Ransom Trojan

What is “Trojan.RansomKD.12582146”?

Malware Removal

The Trojan.RansomKD.12582146 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.12582146 virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to modify browser security settings
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.RansomKD.12582146?


File Info:

crc32: 6437FD97
md5: 9fccf464c3baa38b238f7426a79ec6bc
name: 9FCCF464C3BAA38B238F7426A79EC6BC.mlw
sha1: 9c53ee62f3f40c802aa019bb2222ee886fcdf431
sha256: 48ea5dd49a5666e79dc0c92a19f743a93d88c7d69d46098a6e06bdb8c87cf2bc
sha512: 7b7c92e14626b06c45cacfe9fa93fd3d2226021b4ecd11684dafd65ab00ae3447e62b65a6eb4bec9126a27665960128e1847c57f1df68542d5255a7f2bb06ec2
ssdeep: 24576:AZTZblWdiMLM9o7kWJHxJiyOATJklF5k6wk79mhObiBnMqgY:AZrWdiAN5JriyfSlF5hr7jbiBnP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: 1.exe
FileVersion: 1.0.0.1
CompanyName: -
ProductName: -
ProductVersion: 1.0.0.1
FileDescription: -
OriginalFilename: 1.exe
Translation: 0x0412 0x04b0

Trojan.RansomKD.12582146 also known as:

K7AntiVirusTrojan ( 00517c541 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CylanceUnsafe
ZillyaTrojan.Khalesi.Win32.4023
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00517c541 )
Cybereasonmalicious.4c3baa
SymantecPUA.Ransom
ESET-NOD32a variant of Win32/LockScreen.BQP
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Khalesi.ct
BitDefenderTrojan.RansomKD.12582146
NANO-AntivirusTrojan.Win32.Khalesi.ewdcxk
MicroWorld-eScanTrojan.RansomKD.12582146
TencentWin32.Trojan.Khalesi.Hytw
Ad-AwareTrojan.RansomKD.12582146
SophosMal/Behav-118
ComodoMalware@#7408wk7q9oxl
F-SecureHeuristic.HEUR/AGEN.1100699
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXJJ-BS!C2D6AC96E9B4
FireEyeTrojan.RansomKD.12582146
EmsisoftTrojan.LockScreen (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Script.aizr
AviraHEUR/AGEN.1100699
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.RansomKD.DBFFD02
ZoneAlarmTrojan.Win32.Khalesi.ct
GDataTrojan.RansomKD.12582146
McAfeeArtemis!9FCCF464C3BA
MAXmalware (ai score=100)
VBA32BScope.Trojan.Khalesi
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
RisingTrojan.LockScreen!1.B39F (CLOUD)
YandexTrojan.GenAsa!6u1aK2hN5Zw
IkarusTrojan.RansomKD
FortinetW32/LockScreen.BPL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.RansomKD.12582146?

Trojan.RansomKD.12582146 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment