Trojan

Trojan.RanSerKD.3678640 removal instruction

Malware Removal

The Trojan.RanSerKD.3678640 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RanSerKD.3678640 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Cerber ransomware
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.RanSerKD.3678640?


File Info:

crc32: DC1FC201
md5: 1bd3013e2b2b8e64b4810bdc9bc00d69
name: 1BD3013E2B2B8E64B4810BDC9BC00D69.mlw
sha1: 4a5ab0267007f6bed5c82bd43fd33a297e3d7493
sha256: fbc3ce9b347b7f7fe89bf403a97f3bade2913dd992606cc562f6c25469ab58a6
sha512: 2d98f8cf34f21ea509cd0cb6d485fe310f6b9e098b40a2a1208827450e78b319a6f03ca358603f332edf5da3513010f3b422cf6ed9946eb3ec7348999553372d
ssdeep: 6144:+pkXGhet4gBA9W1I8evbv9BNuzvaoDo6cnuf4ugH:XFt4P9E/er93CSoDoZuf4
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: ZoomToFit (c) http://www.cs.cmu.edu/~maverick/Programs/ZoomToFit
ProductName: ZoomToFit
FileDescription: ZoomToFit For PowerPoint
CompanyName: Maverick Woo
Translation: 0x0409 0x04b0

Trojan.RanSerKD.3678640 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004fc5581 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.6716
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
SangforRansom.Win32.Cerber.mt
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.2178f567
K7GWTrojan ( 004fc5581 )
Cybereasonmalicious.e2b2b8
CyrenW32/Cerber.SVAU-7919
SymantecRansom.Cerber
ESET-NOD32Win32/Filecoder.Cerber.B
ZonerTrojan.Win32.46942
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Zerber.abcn
BitDefenderTrojan.RanSerKD.3678640
NANO-AntivirusTrojan.Win32.Zerber.eijurl
ViRobotTrojan.Win32.S.Cerber.278199
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanTrojan.RanSerKD.3678640
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.RanSerKD.3678640
SophosMal/Generic-R + Troj/Cerber-SZ
ComodoMalware@#2n0nsk35n5jh3
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.QD
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.dc
FireEyeGeneric.mg.1bd3013e2b2b8e64
EmsisoftTrojan.RanSerKD.3678640 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Ransom.Gen
AviraTR/Crypt.XPACK.ylban
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.RanSerKD.D3821B0
AegisLabTrojan.Win32.Zerber.4!c
GDataWin32.Trojan.Agent.06DB7D
TACHYONRansom/W32.Cerber.278199
AhnLab-V3Trojan/Win32.Miuref.C1649597
McAfeeGeneric.zv
MAXmalware (ai score=100)
VBA32Hoax.Zerber
MalwarebytesRansom.Cerber
PandaTrj/WLT.C
TrendMicro-HouseCallRansom_CERBER.QD
RisingTrojan.Spy.Win32.Zerber.a!0.18E18A (KTSE)
IkarusTrojan.Win32.Filecoder
FortinetW32/Injector.JH!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Ransom.Cerber.HyoDEpsA

How to remove Trojan.RanSerKD.3678640?

Trojan.RanSerKD.3678640 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment