Ransom Trojan

Trojan.RansomKD.12582162 (file analysis)

Malware Removal

The Trojan.RansomKD.12582162 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.12582162 virus can do?

  • Network activity detected but not expressed in API logs

How to determine Trojan.RansomKD.12582162?


File Info:

crc32: 218A773C
md5: fd9abbc53b247ccbbbfd22993cfa4b10
name: FD9ABBC53B247CCBBBFD22993CFA4B10.mlw
sha1: 35d939c8bee3a1ddcbb7406825fb4454614f0fcb
sha256: 104b5623d8edd7e56d7e824d900ef57cc085ad7b2935c794af58de87d4f8c2d3
sha512: 3fb29c4276889b49b8956b03303585e2879b9363aca02bae17dc646098284219ceb2424f63e4eb4087a6f80bee9dcf74f761297845d7e1fce80a6466009ace6b
ssdeep: 384:6Z567E+26NJn2WhF+EQV2FZ/bT3aoub+L/4IwPSkMozhzo80uNnokwAcJ78ywAt:g6NJn2WhZxVPazx9npa8+zprEXa
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: RASTAKHIZ Decrypt0r.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: RASTAKHIZ Decrypt0r
ProductVersion: 1.0.0.0
FileDescription: RASTAKHIZ Decrypt0r
OriginalFilename: RASTAKHIZ Decrypt0r.exe

Trojan.RansomKD.12582162 also known as:

K7AntiVirusTrojan ( 0051fbcb1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
McAfeeArtemis!FD9ABBC53B24
CylanceUnsafe
ZillyaTrojan.RansomKD.Win32.243
SangforRansom.Win32.Agent.12582162
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Application/RASTAKHIZ.fdac7a8f
K7GWTrojan ( 0051fbcb1 )
Cybereasonmalicious.53b247
SymantecRansom.HiddenTear!g1
ESET-NOD32a variant of Generik.EAKOMVU
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.RansomKD.12582162
NANO-AntivirusTrojan.Win32.StartPage.evggdb
MicroWorld-eScanTrojan.RansomKD.12582162
TencentWin32.Trojan.Startpage.Egog
Ad-AwareTrojan.RansomKD.12582162
SophosMal/Generic-S
ComodoMalware@#28p1tswolp53
F-SecureTrojan.TR/StartPage.tutjx
BitDefenderThetaGen:NN.ZemsilF.34722.bm0@aar1kJp
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_RASTAKHIZ.A
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.RansomKD.12582162
EmsisoftTrojan.Ransom (A)
SentinelOneStatic AI – Malicious PE
AviraTR/StartPage.tutjx
eGambitUnsafe.AI_Score_97%
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.RansomKD.DBFFD12
GDataTrojan.RansomKD.12582162
MAXmalware (ai score=98)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_RASTAKHIZ.A
YandexTrojan.Agent!kJ2wXAQkTlc
IkarusTrojan.SuspectCRC
FortinetW32/Ransom.ESK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.RansomKD.12582162?

Trojan.RansomKD.12582162 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment