PUA

PUP.Optional.ServiceRNDM removal tips

Malware Removal

The PUP.Optional.ServiceRNDM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.ServiceRNDM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUP.Optional.ServiceRNDM?


File Info:

name: C9B186E00FC877F876E9.mlw
path: /opt/CAPEv2/storage/binaries/697d0a7a1e9839992b734ca345b8b073ff2d4ca3446aec94f7e8c31c0f5df4c6
crc32: 749ED83A
md5: c9b186e00fc877f876e969ab4f1174ab
sha1: 13bcb476b4be06d001f7e44f58dac12a16fed8b5
sha256: 697d0a7a1e9839992b734ca345b8b073ff2d4ca3446aec94f7e8c31c0f5df4c6
sha512: 6b6e88b0f303c36ab4ee8374d4a747e0f7c92023f5be057e1cf254237d02403d87040697d42f9bba4a71cd7882d153026703c1a43f4b4ef39d2f7a8486667899
ssdeep: 98304:u/kQHjkHJxQINy9KPPb5HGxvwMTSgaqH0rUJ2u0W9qa:u/XkpxQIY9KPwxZv2u0W9qa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1861290AB42D0B1CD990DF851AB56B61F708E00B727B9D3C5A87D88D6732F0567E38E
sha3_384: 65f7e8fe3b8ee6eb53a641eb71ca76116f01737cb3739bee332320569ed30d4a1368cba1db98afde270a04afa52fd16e
ep_bytes: e872030000e936fdffff8bff558bec8b
timestamp: 2008-11-10 09:40:35

Version Info:

0: [No Data]

PUP.Optional.ServiceRNDM also known as:

BkavW32.FamVT.MambaHV.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mamba.1
FireEyeGen:Variant.Mamba.1
CAT-QuickHealTrojan.Blakamba.A4
ALYacGen:Variant.Mamba.1
MalwarebytesPUP.Optional.ServiceRNDM
VIPREGen:Variant.Mamba.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004ce8ce1 )
K7GWTrojan ( 004ce8ce1 )
CyrenW32/Agent.AIE.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Python/Mamba.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Mamba.1
NANO-AntivirusTrojan.Script.Agent.dxolwd
AvastWin32:Agent-BBTH [Trj]
TencentTrojan.Win32.Mamba.ya
EmsisoftGen:Variant.Mamba.1 (B)
F-SecureTrojan.TR/Blakamba.Gen
ZillyaTrojan.BlackGen.Win32.13
TrendMicroTROJ_AGENT_EK24001A.UVPM
McAfee-GW-EditionTrojan-FIIH!C9B186E00FC8
Trapminemalicious.high.ml.score
SophosTroj/Blakamba-A
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Mamba.1
WebrootPua.Gen
AviraTR/Blakamba.Gen
MAXmalware (ai score=82)
ArcabitTrojan.Mamba.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Blakamba
GoogleDetected
AhnLab-V3Win-Trojan/Blakamba.Gen
McAfeeTrojan-FIIH!C9B186E00FC8
VBA32Trojan.Blakamba
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_AGENT_EK24001A.UVPM
IkarusTrojan.Win32.Blakamba
MaxSecureTrojan.Malware.7164915.susgen
FortinetPython/Mamba.G!tr
AVGWin32:Agent-BBTH [Trj]
DeepInstinctMALICIOUS

How to remove PUP.Optional.ServiceRNDM?

PUP.Optional.ServiceRNDM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment