Trojan

Trojan.RanSerKD.3711804 removal guide

Malware Removal

The Trojan.RanSerKD.3711804 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RanSerKD.3711804 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Cerber ransomware
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.RanSerKD.3711804?


File Info:

crc32: 587A362B
md5: e8b0bbd9617ab3b43b65a09c2ec4a882
name: E8B0BBD9617AB3B43B65A09C2EC4A882.mlw
sha1: bd7080e672ff9cddfd8dfad2555111898daa93d9
sha256: 147e54a51effe8a0cb42691e0e967752698b4db5883532f88daed9ba4f8b69a7
sha512: 521c8700ae29fd8d37e83b2c1d3137412811706b6d1e27d7b74857a272f67324b9714a0e0c48b9b6036d999fc68a80bd1f29db6acd671aded8f4b82bbc32250d
ssdeep: 6144:ry9v17kwzpAnBMJHKUtAvgPpZURFxMgyWL5E/qoV:m97kGAeKUtIIsRFxmWL5E/qS
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan.RanSerKD.3711804 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.B
ALYacTrojan.RanSerKD.3711804
ZillyaDropper.Generic.Win32.2772
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.9617ab
CyrenW32/Cerber.AD1.gen!Eldorado
SymantecRansom.Cerber
ESET-NOD32NSIS/Injector.KH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.RanSerKD.3711804
NANO-AntivirusTrojan.Nsis.Inject.eiqoul
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanTrojan.RanSerKD.3711804
Ad-AwareTrojan.RanSerKD.3711804
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.dc
FireEyeGeneric.mg.e8b0bbd9617ab3b4
EmsisoftTrojan.RanSerKD.3711804 (B)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.RanSerKD.D38A33C
GDataWin32.Trojan-Ransom.Cerber.BMI6W9
TACHYONRansom/W32.Cerber.271699
McAfeeArtemis!E8B0BBD9617A
MAXmalware (ai score=80)
PandaTrj/CI.A
FortinetW32/Injector.LC!tr
AVGWin32:Trojan-gen

How to remove Trojan.RanSerKD.3711804?

Trojan.RanSerKD.3711804 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment