Trojan

About “Trojan.RanSerKD.3525047” infection

Malware Removal

The Trojan.RanSerKD.3525047 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RanSerKD.3525047 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete or modify volume shadow copies
  • Behavioural detection: Injection (inter-process)
  • Exhibits behavior characteristic of Cerber ransomware

How to determine Trojan.RanSerKD.3525047?


File Info:

name: 3D2FD850DC29D6300732.mlw
path: /opt/CAPEv2/storage/binaries/980386b3798fb4d8c0f09fe0503e23efa7ec5e6f32ee9e500a7394e3daf7a916
crc32: 399CC0A8
md5: 3d2fd850dc29d63007322281f1043259
sha1: 11c825dd416452a6af614ed3ccab0575d2904d98
sha256: 980386b3798fb4d8c0f09fe0503e23efa7ec5e6f32ee9e500a7394e3daf7a916
sha512: eb5448e3d80b05b550675f07dbb93aa444c65b3f70c1aad7a0307ffe533826b7e8a070e66d36758be8a48596bd4eb717210aa311e0d62262333198de4d5ad835
ssdeep: 6144:5n/L+Xtf6vVJDlX17bqInXxXtNDbKlys5ard0xzC0J3:xYtfyNl1TB3KwsErdiXR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109641253B394D073C9B612310EFC4E36FFB9CF21019CA48F9B92765DACB74926A16285
sha3_384: 336c5c861df6d614e12334244e832238d0ab091f41b801a7caacf22af1392ea5e650c5afc53d46f670d4c4b340f17a30
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2014-05-11 20:05:39

Version Info:

0: [No Data]

Trojan.RanSerKD.3525047 also known as:

LionicTrojan.Win32.Zerber.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.RanSerKD.3525047
FireEyeGeneric.mg.3d2fd850dc29d630
CAT-QuickHealRansom.Onion.B
ALYacTrojan.RanSerKD.3525047
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojan:Win32/Injector.a7f3cc75
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.0dc29d
BitDefenderThetaGen:NN.ZedlaF.34182.gy8@ayteMWm
VirITTrojan.Win32.Ransom_c.BHH
SymantecTrojan.Malcol.Ransom.2
ESET-NOD32a variant of Win32/Injector.DFAS
TrendMicro-HouseCallRansom_CERBER.F116IQ
Paloaltogeneric.ml
ClamAVWin.Dropper.Cerber-9845751-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.RanSerKD.3525047
NANO-AntivirusTrojan.Win32.Agent.egzadw
SUPERAntiSpywareRansom.Cerber/Variant
APEXMalicious
TencentWin32.Trojan.Zerber.Lkod
EmsisoftTrojan.RanSerKD.3525047 (B)
ComodoMalware@#3p4p1qr42x823
F-SecureHeuristic.HEUR/AGEN.1109160
DrWebTrojan.Click3.25793
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.F116IQ
McAfee-GW-EditionGenericRXGB-RI!4BEE92E36920
SophosMal/Generic-R + Mal/Miuref-L
WebrootW32.Ransomware.Cerber
AviraHEUR/AGEN.1124292
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.BTSGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Cerber
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.RanSerKD.3525047
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.R187973
McAfeeArtemis!3D2FD850DC29
VBA32TrojanRansom.Enestedel
MalwarebytesGeneric.Malware/Suspicious
AvastFileRepMalware
RisingRansom.Enestedel!8.E513 (CLOUD)
YandexTrojan.Injector!+1bb52pW8dQ
FortinetW32/Injector.DFAS!tr
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.RanSerKD.3525047?

Trojan.RanSerKD.3525047 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment