Ransom Trojan

Should I remove “Trojan.RansomKD.5630936”?

Malware Removal

The Trojan.RansomKD.5630936 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.5630936 virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.RansomKD.5630936?


File Info:

crc32: 8D261165
md5: 90cbd0c91d0abcbc35d49ad910e799f1
name: 90CBD0C91D0ABCBC35D49AD910E799F1.mlw
sha1: 8050ee53aba2ca7a79f6290ccf6d762b074ec5fc
sha256: a23f9dab05998c2f4ca288005f6ee917a6e5b2a6492186c3b3bcfff5eb153bdb
sha512: 25869a3b934ec48f56c113d3aa99b4a7721f7445b29b73f2136b0c3163aa5f1ba04e39b0e949113e85d1220f812473cd627070131fe20fa9620698144473d738
ssdeep: 24576:xOuww24Ek/VQkGGzLkNun0FV3/bbPb6w/o5yD3CSFZclVerpC4I8qUhGorgW7nWV:kuwh4EWh0NLFZ/5gD3Vz4I8G5knmJSs9
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: oft invited me
InternalName: Still question'd me
FileVersion: 39.22.24.2022
CompanyName: Her father loved me
ProductName: How I did thrive
ProductVersion: 39.22.24.2022
FileDescription: the story of my life
Translation: 0x0409 0x04b0

Trojan.RansomKD.5630936 also known as:

K7AntiVirusAdware ( 0050dc921 )
Elasticmalicious (high confidence)
DrWebTrojan.StartPage1.42282
CynetMalicious (score: 100)
ALYacTrojan.RansomKD.5630936
CylanceUnsafe
ZillyaTrojan.RansomKD.Win32.321
SangforTrojan.Win32.Generic.5
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaAdWare:Win32/HPDefender.99dce5db
K7GWAdware ( 0050dc921 )
Cybereasonmalicious.91d0ab
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Adware.HPDefender.ANS
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderTrojan.RansomKD.5630936
NANO-AntivirusTrojan.Win32.Symmi.epeals
SUPERAntiSpywareAdware.HPDefender/Variant
MicroWorld-eScanTrojan.RansomKD.5630936
TencentWin32.Adware.Generic.Htcd
Ad-AwareTrojan.RansomKD.5630936
SophosGeneric ML PUA (PUA)
ComodoMalware@#3g4giptfyp9gk
BitDefenderThetaGen:NN.ZexaF.34692.jC0@amMzY7hi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.ICLoader.tc
FireEyeGeneric.mg.90cbd0c91d0abcbc
EmsisoftTrojan.RansomKD.5630936 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117985
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.2038338
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.RansomKD.D55EBD8
GDataTrojan.RansomKD.5630936
AhnLab-V3PUP/Win32.ICLoader.R199572
McAfeeICLoader
MAXmalware (ai score=80)
VBA32Adware.Presenoker
MalwarebytesAdware.HPDefender
PandaTrj/Genetic.gen
RisingMalware.Generic.5!tfe (C64:YzY0Olrj2iONzaUL)
YandexTrojan.GenAsa!ZQTfB2K980c
FortinetRiskware/HPDefender
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Trojan.RansomKD.5630936?

Trojan.RansomKD.5630936 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment