Ransom Trojan

Trojan.RansomKD.6246301 removal tips

Malware Removal

The Trojan.RansomKD.6246301 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.6246301 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Deletes its original binary from disk
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.RansomKD.6246301?


File Info:

crc32: 5E1B5D8C
md5: a46839447d4902b121ec094d9266967b
name: A46839447D4902B121EC094D9266967B.mlw
sha1: 4a5590df4bbeb8c16830443600bb6b66d9560ffe
sha256: 09ce12cac6e432959a9965630d2d83d66be771106f54423baf33963a6de13b58
sha512: a6c06f3cf61a2d61b47082f8a0ce00a1c3f3765256249954479fba2aefb4b2db6cb3f4787644d33545aa59403272a3a64e9de2e0558510a14aa41cebd51bec35
ssdeep: 3072:eCfXDDGTcuBy+FlHad34zuMJzA30FCSukvFK8X4ANpGE6BtXnhO70TGg:eCfXyzy+F+Ak30FxuiKADHGh3kc
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan.RansomKD.6246301 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0051d84c1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacTrojan.RansomKD.6246301
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Injector.f9b3ea83
K7GWTrojan ( 0051d84c1 )
Cybereasonmalicious.47d490
SymantecPacked.NSISPacker!g4
ESET-NOD32NSIS/Injector.VL
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.RansomKD.6246301
NANO-AntivirusTrojan.Win32.ObfusRansom.fgahcx
MicroWorld-eScanTrojan.RansomKD.6246301
TencentWin32.Trojan.Generic.Llgy
Ad-AwareTrojan.RansomKD.6246301
SophosMal/Generic-R + Mal/Cerber-AA
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.cc
FireEyeGeneric.mg.a46839447d4902b1
EmsisoftTrojan.RansomKD.6246301 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bgyzr
AviraHEUR/AGEN.1131933
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.RansomKD.6246301
McAfeeArtemis!A46839447D49
MAXmalware (ai score=99)
PandaTrj/CI.A
FortinetW32/Injector.UQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.RansomKD.6246301?

Trojan.RansomKD.6246301 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment