Trojan

Trojan.RanSerKD.40170223 (file analysis)

Malware Removal

The Trojan.RanSerKD.40170223 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RanSerKD.40170223 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.RanSerKD.40170223?


File Info:

crc32: AEE2AFB4
md5: ad5f7e2fee937d3a10e18a22824cc970
name: AD5F7E2FEE937D3A10E18A22824CC970.mlw
sha1: 8f9efcaa416d20dc977c986e26c3cb5ec3d5ae78
sha256: 117d471c07f4cf16121b8868a22b6a548196c31d9a5f39b57f5104cbe9f638fa
sha512: 1a167fac4fa845538f221acb6669643562e3e7e991c241a02bc1cbfe0e682c5150f2ef31defad5e4e57e01430595aea116c82356b9294430fc186b994c6127d4
ssdeep: 3072:8yl+s04LWSanDN0Loj/pWcHnpEA1oAdJDqLFWMbiPfna5tD/S:8WElSansojZnGqoAjQwP0D
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Enforcement
InternalName: whoreson
FileVersion: 4.10.0.39742
CompanyName: Enforcement
ProductName: whoreson feverfews
ProductVersion: 4.10.0.39742
FileDescription: whoreson ichthus
OriginalFilename: whoreson.exe
Translation: 0x0409 0x04b0

Trojan.RanSerKD.40170223 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f07d41 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacTrojan.RanSerKD.40170223
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Zerber.153fcf17
K7GWTrojan ( 004f07d41 )
Cybereasonmalicious.fee937
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EYKI
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.fewn
BitDefenderTrojan.RanSerKD.40170223
NANO-AntivirusTrojan.Win32.Kryptik.eveeae
MicroWorld-eScanTrojan.RanSerKD.40170223
TencentWin32.Trojan.Zerber.Lohz
Ad-AwareTrojan.RanSerKD.40170223
SophosML/PE-A + Mal/Cerber-C
ComodoMalCrypt.Indus!@1qrzi1
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Zerber.R002C0PG121
McAfee-GW-EditionRansomware-GIX!AD5F7E2FEE93
FireEyeGeneric.mg.ad5f7e2fee937d3a
EmsisoftTrojan.RanSerKD.40170223 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.drn
AviraHEUR/AGEN.1117690
MicrosoftRansom:Win32/Cerber
AegisLabTrojan.Win32.Zerber.j!c
ZoneAlarmTrojan-Ransom.Win32.Zerber.fewn
GDataTrojan.RanSerKD.40170223
AhnLab-V3Trojan/Win32.Zerber.C2267710
McAfeeRansomware-GIX!AD5F7E2FEE93
MAXmalware (ai score=99)
VBA32Malware-Cryptor.Limpopo
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Zerber.R002C0PG121
RisingTrojan.Generic@ML.97 (RDML:pOQUA9G2RvIt2d2TQu1+3Q)
YandexTrojan.GenAsa!hVxXPoRErOw
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBEpsA

How to remove Trojan.RanSerKD.40170223?

Trojan.RanSerKD.40170223 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment