Ransom Trojan

How to remove “Trojan.RansomKD.5941299”?

Malware Removal

The Trojan.RansomKD.5941299 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.5941299 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.RansomKD.5941299?


File Info:

crc32: E10ED62D
md5: 17f5da46dfd5015fd6ee83a9c41fc7f2
name: 17F5DA46DFD5015FD6EE83A9C41FC7F2.mlw
sha1: ae3cc5dad63319f94d673246d648d9758ae703b5
sha256: dcc2d5fad70bb9f6a3a02de326520bb81d94edfb3533818deb13191db2088663
sha512: be4ff38b3329b71a44ab879574341cea2db411767c933b9468316a95512212e44896d5d94e0bb973e6ff4511adb3bc02e68f0f64b8c16f17f6850d752e72cc3c
ssdeep: 3072:mD4iRFGP+tbL8JcHlM/JlsM6hsCRqXwiqgNg4nf9Jp:obnnWJlsJhDqgpYg4fN
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan.RansomKD.5941299 also known as:

ALYacTrojan.RansomKD.5941299
CylanceUnsafe
SangforRansom.Win32.Agent.5941299
AlibabaRansom:Win32/Generic.7b1d09c0
Cybereasonmalicious.6dfd50
SymantecTrojan.Gen.7
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.erq
BitDefenderTrojan.RansomKD.5941299
MicroWorld-eScanTrojan.RansomKD.5941299
TencentWin32.Trojan.Gen.Ebhl
Ad-AwareTrojan.RansomKD.5941299
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.cc
FireEyeTrojan.RansomKD.5941299
EmsisoftTrojan.RansomKD.5941299 (B)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftExploit:Linux/Lotoor.A!MTB
ArcabitTrojan.RansomKD.D5AA833
AegisLabTrojan.Win32.Generic.j!c
GDataTrojan.RansomKD.5941299
McAfeeArtemis!17F5DA46DFD5
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Gen
PandaTrj/CI.A
AVGWin32:Malware-gen

How to remove Trojan.RansomKD.5941299?

Trojan.RansomKD.5941299 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment