Ransom Trojan

Trojan.RansomKD.6199215 removal instruction

Malware Removal

The Trojan.RansomKD.6199215 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.6199215 virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.RansomKD.6199215?


File Info:

crc32: 81874C9B
md5: 9b6721644f3df99231a70b0075696af9
name: 9B6721644F3DF99231A70B0075696AF9.mlw
sha1: de39ea3f616011be41b3dd00128917687362f040
sha256: 8f60ca0fe0ad4be06f257b22d46f5798c22f8cc049cab3ee65cb2e0765c3dc57
sha512: 9231e35b6f97ca25f842046d52fbbb580536395c13ffdf8ebc5c10a89a383175c8c4b3cf359102d39631e8cb963042181c11d9ec896ab2fcc483fc4d82b1b783
ssdeep: 6144:4ciEde2K/IyHwihFp7non6YpjUaKwtapzVQY9VVa6:zF/K/IyHpbSi3Qm/9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 MrFreeCrypt
InternalName:
FileVersion:
CompanyName:
PrivateBuild: May 17, 2012
ProductName: MrFreeCrypt
ProductVersion: 1.4.4.2485
FileDescription:
OriginalFilename: x86.exe
Translation: 0x0000 0x04b0

Trojan.RansomKD.6199215 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005201651 )
DrWebTrojan.Click2.41712
CynetMalicious (score: 85)
ALYacTrojan.RansomKD.6199215
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Ransomware.5d130d04
K7GWTrojan ( 005201651 )
Cybereasonmalicious.44f3df
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NQATMQU
APEXMalicious
AvastVBS:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.RansomKD.6199215
NANO-AntivirusTrojan.Win32.MiFiles.euzgmm
MicroWorld-eScanTrojan.RansomKD.6199215
TencentWin32.Trojan.Generic.Huzf
Ad-AwareTrojan.RansomKD.6199215
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDropper.MrFreeCrypt.0@4s2hd0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-FQO!9B6721644F3D
FireEyeTrojan.RansomKD.6199215
EmsisoftTrojan.RansomKD.6199215 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1132407
MicrosoftTrojan:Win32/Tiggre!rfn
GDataTrojan.RansomKD.6199215
AhnLab-V3Trojan/Win32.Ruftar.R42301
McAfeeRansomware-FQO!9B6721644F3D
MAXmalware (ai score=100)
PandaTrj/CI.A
YandexTrojan.Pakes!RpzpHFEp/Sg
FortinetRansomware.FQO!tr
AVGVBS:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASOUA

How to remove Trojan.RansomKD.6199215?

Trojan.RansomKD.6199215 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment