Ransom Trojan

Trojan.RansomKD.5956160 malicious file

Malware Removal

The Trojan.RansomKD.5956160 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.5956160 virus can do?

  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Trojan.RansomKD.5956160?


File Info:

crc32: D4E48350
md5: b1ed9923d610ad8c2911bebdbb9d177e
name: B1ED9923D610AD8C2911BEBDBB9D177E.mlw
sha1: c6300a64029671a37a192b862e8f3ca20b9525c2
sha256: 32e4cde5e9ba2cb521479beecdb3a46504b0608401327e7f2b9c0e6306990ab5
sha512: 06f8b9f6c0eccb91d96ad55daca48c01469994413252247db1a76a354b4e4918c5b8b4bb6397e01458cf20fa57ba594ef7a1a672c35e9edb554b56a4b683744a
ssdeep: 6144:RVOfZTZiOydo+h9g1V5M4orn+GrtY36V7w5KjM9AC9LzfMwHkQgXzQ41sHIErSc:zozGdX0M4ornOmZIzfMwHkQmz9soarr
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: #NVJOB
ProductVersion: 0.1.5
FileVersion: 0.0.1.5
Comments: CW Frame RU
FileDescription: CW Frame RU
Translation: 0x0419 0x04b0

Trojan.RansomKD.5956160 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
ALYacTrojan.RansomKD.5956160
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:AutoIt/Generic.fe601a88
Cybereasonmalicious.3d610a
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.RansomKD.5956160
NANO-AntivirusTrojan.Win32.AutoIt.esnhvt
MicroWorld-eScanTrojan.RansomKD.5956160
TencentWin32.Trojan.Generic.Pgcz
Ad-AwareTrojan.RansomKD.5956160
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.gc
FireEyeGeneric.mg.b1ed9923d610ad8c
EmsisoftTrojan.RansomKD.5956160 (B)
AviraDR/AutoIt.Gen
eGambitUnsafe.AI_Score_59%
MicrosoftTrojan:Win32/Ymacco.AA10
GDataTrojan.RansomKD.5956160
McAfeeArtemis!B1ED9923D610
MAXmalware (ai score=99)
PandaTrj/CI.A
IkarusDropper.AutoIt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.RansomKD.5956160?

Trojan.RansomKD.5956160 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment