Ransom Trojan

Trojan.RansomKD.6246744 (file analysis)

Malware Removal

The Trojan.RansomKD.6246744 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.6246744 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to remove evidence of file being downloaded from the Internet
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.RansomKD.6246744?


File Info:

crc32: FD2E5924
md5: a4c51cf8c42f82968dc35ba5d8e9566f
name: A4C51CF8C42F82968DC35BA5D8E9566F.mlw
sha1: a824d2c01aa4594535f084e4f8b2958f1b325383
sha256: 3cddbc522a3b13dffc4668d7bc506808be54213d78f6eb7a80489f47606c01de
sha512: 45bfec395ad58925da459025859ecd49a668d0d7a2b8fca0be3366df79f3fe8892e007bd8c0547e9e4d5d35e2ab46a745bbed2ddc5b825a09669783e2b6cd7ff
ssdeep: 12288:uR+/Ym7BrxULdeaVlBM+C+KLZ5+p/wEAoT2M3J:BYmdru3Y5+p/wEAKJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Copyright 2009, NLnet Labs
FileVersion: 0.0.0.0
CompanyName: NLnet Labs
ProductName: Unbound
ProductVersion: 0.0.0.0
FileDescription: (un)install the unbound DNS resolver
Translation: 0x0409 0x04b0

Trojan.RansomKD.6246744 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
CynetMalicious (score: 100)
ALYacTrojan.RansomKD.6246744
CylanceUnsafe
SangforTrojan.Win32.Injector.tizs
CrowdStrikewin/malicious_confidence_80% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8c42f8
SymantecTrojan.Gen.2
ESET-NOD32a variant of Generik.DOUAAMS
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Dropper.Win32.Injector.tizs
BitDefenderTrojan.RansomKD.6246744
NANO-AntivirusTrojan.Win32.Kronos.exizgu
MicroWorld-eScanTrojan.RansomKD.6246744
TencentWin32.Trojan-dropper.Injector.Lnnx
Ad-AwareTrojan.RansomKD.6246744
SophosML/PE-A + Mal/Miuref-L
TrendMicroRansom_CERBERENC.SMNS5
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.fc
FireEyeGeneric.mg.a4c51cf8c42f8296
EmsisoftTrojan.RansomKD.6246744 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1102533
MicrosoftBackdoor:Win32/Konus.A
SUPERAntiSpywareRansom.FileCryptor/Variant
GDataTrojan.RansomKD.6246744
AhnLab-V3Trojan/Win32.MDA.R188938
McAfeeArtemis!A4C51CF8C42F
MAXmalware (ai score=95)
MalwarebytesRansom.Cerber
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBERENC.SMNS5
FortinetW32/Injector.GD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Inject.HyoDtD8A

How to remove Trojan.RansomKD.6246744?

Trojan.RansomKD.6246744 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment