Ransom Trojan

Trojan.RansomKD.5647204 (B) removal tips

Malware Removal

The Trojan.RansomKD.5647204 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.5647204 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.RansomKD.5647204 (B)?


File Info:

name: 59C1F6470D34EAF85189.mlw
path: /opt/CAPEv2/storage/binaries/3d8daa61f54a63ff6377a88261d6531203c991c5a1fc184c0cdd8c200e067a19
crc32: B40E3ED6
md5: 59c1f6470d34eaf851892e727bf54696
sha1: cf91051b0a7099c498de109bf158044b8b4a5690
sha256: 3d8daa61f54a63ff6377a88261d6531203c991c5a1fc184c0cdd8c200e067a19
sha512: 174ced8107566e1e7c3b0a3a1a4ad58bb68d01a6676025b28c88e0fde9814ccad747ca4a3465173a4093d51118c837315a1d139974b1fb8e17b5c072ef878254
ssdeep: 12288:wjp/dUVBjakkkkkkk2SHezi228+BSg7SKJaUOVzlvefgKrF3JYRDTyhkn6CCXp7z:wjp/dUDYSHe220Eg+KUCFrICGI1z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1111512196151698BEE6944B08076C370822E7D43B2E55D47FBD6BF5B3BF08A70B6E203
sha3_384: f75369fb015c8860df117bfb3d0a7909062d2e2c77d4db900a90f2b1e481401d250037da0d12591b3ee3374810e87485
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-06 21:41:59

Version Info:

0: [No Data]

Trojan.RansomKD.5647204 (B) also known as:

LionicTrojan.Win32.RansomKD.4!c
MicroWorld-eScanTrojan.RansomKD.5647204
FireEyeTrojan.RansomKD.5647204
McAfeeArtemis!59C1F6470D34
CylanceUnsafe
SangforPUP.Win32.Vigua.A
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.70d34e
CyrenW32/Trojan.QOKH-0350
SymantecTrojan.Gen.2
APEXMalicious
BitDefenderTrojan.RansomKD.5647204
AvastFileRepMalware [Trj]
Ad-AwareTrojan.RansomKD.5647204
EmsisoftTrojan.RansomKD.5647204 (B)
ZillyaTrojan.Onion.Win32.1532
McAfee-GW-EditionBehavesLike.Win32.BadFile.dc
SophosGeneric Reputation PUA (PUA)
GDataTrojan.RansomKD.5647204
WebrootW32.Gen.BT
MAXmalware (ai score=86)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.RansomKD.D562B64
MicrosoftPUA:Win32/Vigua.A
ALYacTrojan.RansomKD.5647204
TACHYONRansom/W32.Agent.950511
VBA32Hoax.Onion
TrendMicro-HouseCallTROJ_GEN.R002H09E722
AVGFileRepMalware [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.RansomKD.5647204 (B)?

Trojan.RansomKD.5647204 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment