Ransom Trojan

About “Trojan.RansomKD.6195369” infection

Malware Removal

The Trojan.RansomKD.6195369 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.6195369 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics

How to determine Trojan.RansomKD.6195369?


File Info:

crc32: EA402F6C
md5: 0bcb800a7b708fb073a5da8553bc3e14
name: 0BCB800A7B708FB073A5DA8553BC3E14.mlw
sha1: 62d4c74e5c7c32cc47c54256c03e70c4dcf546c5
sha256: 8e9050661390390bd710c66b3eff860d53fa728b012010325e9c8e1d7ba7a078
sha512: 67d1cd4beb28dae8e24a525eaf2e3eef6328307bba154590784ab09ee8762f40cd06edb0cbd57eca6dbaeac39cd9ef23a8243356efe598f36edbd77104a648d6
ssdeep: 1536:snw8RSijDtSA5xeZ0DbBCc1p0Z3hSzgG995rJGiV4DvBbNZyBoALBZDt7dPG:QwDijpS4DbYc1p83gh995JGivVm
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright:
FileVersion: 1.2.55
CompanyName:
LegalTrademarks: Clear Registry Chat Application is a trademark of a@F5r
Comments: Registry
ProductName: Clear Registry Chat
FileDescription:
Translation: 0x0409 0x04e4

Trojan.RansomKD.6195369 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.KillFiles.61879
CynetMalicious (score: 99)
ALYacTrojan.RansomKD.6195369
CylanceUnsafe
ZillyaTrojan.RansomKD.Win32.270
SangforRansom.Win32.Agent.6195369
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a7b708
CyrenW32/DotDo.AG.gen!Eldorado
SymantecRansom.Cry
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.RansomKD.6195369
MicroWorld-eScanTrojan.RansomKD.6195369
Ad-AwareTrojan.RansomKD.6195369
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.mc
FireEyeTrojan.RansomKD.6195369
EmsisoftTrojan.RansomKD.6195369 (B)
AviraTR/KillFiles.wnyqo
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.RansomKD.D5E88A9
AegisLabTrojan.Win32.Agent.4!e
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.RansomKD.6195369
McAfeeArtemis!0BCB800A7B70
MAXmalware (ai score=100)
VBA32Win32.Trojan.Hoster.Heur
PandaTrj/CI.A
SentinelOneStatic AI – Suspicious PE
FortinetW32/Generic!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.KillFiles.HoMASSkA

How to remove Trojan.RansomKD.6195369?

Trojan.RansomKD.6195369 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment