Trojan

About “Trojan:Win32/Kangkio.D” infection

Malware Removal

The Trojan:Win32/Kangkio.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Kangkio.D virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Kangkio.D?


File Info:

name: AFEFF3F5811861F211A4.mlw
path: /opt/CAPEv2/storage/binaries/8d34bcd5a70a6160b324c10b07c95094d0e0eb8ee948ad0fcf53a63145e7eda3
crc32: C95EB8A2
md5: afeff3f5811861f211a4ab96554ad420
sha1: 638d60b00a28b056250b85d71d486f2d3c9771d5
sha256: 8d34bcd5a70a6160b324c10b07c95094d0e0eb8ee948ad0fcf53a63145e7eda3
sha512: a5dc4b20832b9d6f01650597cd980f7bf5684a82bafc89e8a433736d8be840122b4c2de69d3fed73612d0c1940d65a82f66ff3db3062417951314fcffb6cef29
ssdeep: 192:ERQQB38uC8UKXRFEvIoMLAh4qRVcKAh4KP1oynK6Yd52DmJU0:tQB38YHXXPOqj1FY00
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FB2C64FEA054471CBD8C1331AAF1B78C672958607B89A872B94FD4C3C3E26156B714E
sha3_384: 9feb3c1747a7beb5fb76a3308fc8d424c18c7b2d4546f2d18c0f550a0b2e469ea61fc4fb09316b534e3d98c352efd8ac
ep_bytes: 558bec6aff68c0354000687624400064
timestamp: 2008-08-21 17:43:25

Version Info:

0: [No Data]

Trojan:Win32/Kangkio.D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Genome.a!c
AVGWin32:DropperX-gen [Drp]
DrWebTrojan.DownLoad1.40658
MicroWorld-eScanGen:Variant.Graftor.864659
FireEyeGeneric.mg.afeff3f5811861f2
SkyhighBehavesLike.Win32.Generic.mz
McAfeeArtemis!AFEFF3F58118
MalwarebytesGeneric.Malware/Suspicious
ZillyaDownloader.Agent.Win32.32782
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Win32/Genome.8c21969e
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36802.bqX@aOKjGYib
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.LIVEIVK
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan-Downloader.Win32.Genome.shct
BitDefenderGen:Variant.Graftor.864659
NANO-AntivirusTrojan.Win32.Agent.qkie
TencentMalware.Win32.Gencirc.1402f122
EmsisoftGen:Variant.Graftor.864659 (B)
F-SecureTrojan.TR/Downloader.Gen
VIPREGen:Variant.Graftor.864659
TrendMicroTROJ_AGENT.ASLE
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.evnf
VaristW32/Downloader.PGDV-0811
AviraTR/Downloader.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Agent
KingsoftWin32.HeurC.KVMH017.a
MicrosoftTrojan:Win32/Kangkio.D
XcitiumMalware@#zzuhj3tko1u5
ArcabitTrojan.Graftor.DD3193
ViRobotTrojan.Win32.Downloader.24576.AGY
ZoneAlarmTrojan-Downloader.Win32.Genome.shct
GDataGen:Variant.Graftor.864659
GoogleDetected
AhnLab-V3Downloader/Win32.Agent.C25081
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Graftor.864659
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_AGENT.ASLE
RisingTrojan.Kangkio!8.51A0 (TFE:5:VXv9dX0ZzaK)
YandexTrojan.DL.Agent!FTGSAq6PW7A
IkarusTrojan-Downloader
MaxSecureTrojan.Malware.2037551.susgen
FortinetW32/Agent.AJAI!tr.dldr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Genome.shct

How to remove Trojan:Win32/Kangkio.D?

Trojan:Win32/Kangkio.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment