Ransom Trojan

Trojan.RansomKD.6247185 (file analysis)

Malware Removal

The Trojan.RansomKD.6247185 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RansomKD.6247185 virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.RansomKD.6247185?


File Info:

crc32: 0ED8BA48
md5: dfaf407058ad367af57290862e76a8ca
name: DFAF407058AD367AF57290862E76A8CA.mlw
sha1: 39c595d4cd9f451e2780fb36692a6b4e4eb889b3
sha256: 74fd72ed46d7c42f05ef894ddbf5e4b5e592c4f481a0d4641342b4bd3e242ebe
sha512: 7834bd07b7276204d7d5afa1256be2fb0b5eec8f22c5162cbf55e426803fcaddff775ee6a8cef195aba5de2d973fa81954eeb13625ccffca47b0c87885fdb9d6
ssdeep: 96:mDw72YvEG//4BH3L6y+gccVyYF+IiKtkNo6SCRG/tcs2vKPQzUPpPrmfm:mE2k4B76y+WyY9kMLtdDPQahr8m
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: zfgzgzyylt.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: rgergerge.exe
Translation: 0x040c 0x04b0

Trojan.RansomKD.6247185 also known as:

LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 99)
ALYacTrojan.RansomKD.6247185
CylanceUnsafe
AlibabaTrojan:Win32/StartPage.f0fab8af
Cybereasonmalicious.058ad3
SymantecTrojan Horse
ESET-NOD32a variant of Generik.NIYLSUI
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.RansomKD.6247185
NANO-AntivirusTrojan.Win32.StartPage.ewkmtt
MicroWorld-eScanTrojan.RansomKD.6247185
TencentWin32.Trojan.Ransomkd.Wvut
Ad-AwareTrojan.RansomKD.6247185
SophosMal/Generic-S
ComodoMalware@#gsbht37jd121
BitDefenderThetaGen:NN.ZexaF.34170.au0@aKlzjrfm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic StartPage.cf
FireEyeTrojan.RansomKD.6247185
EmsisoftTrojan.RansomKD.6247185 (B)
AviraHEUR/AGEN.1102646
MicrosoftTrojan:Win32/Ymacco.AA74
GDataTrojan.RansomKD.6247185
AhnLab-V3Malware/Win32.Generic.C2383746
McAfeeRDN/Generic StartPage.cf
MAXmalware (ai score=100)
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.84 (RDML:x5XvVN5UfTUmsgL/7XSOIA)
IkarusTrojan.SuspectCRC
FortinetGenerik.NIYLSUI!tr
AVGWin32:Malware-gen

How to remove Trojan.RansomKD.6247185?

Trojan.RansomKD.6247185 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment