Trojan

Trojan.RanSerKD.4048950 removal guide

Malware Removal

The Trojan.RanSerKD.4048950 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RanSerKD.4048950 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • PlugX
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.RanSerKD.4048950?


File Info:

crc32: 5194FB6C
md5: 1dec2acddb9734e65b9694a144f98701
name: 1DEC2ACDDB9734E65B9694A144F98701.mlw
sha1: d9ac6c070a0ae044635918bbef94c66656dba8f9
sha256: 384b89f1cf6cddeda7a5c05c23ac5709588bd341f329d48dae6eab228b444ef3
sha512: ed8770885be04923467620d1da78bf23de5bbef545c8ba01889b76aa77b37def48c991deed8745f7122a7c188cd3e9409c73f8626856c96c6f2cc170634a6bc2
ssdeep: 6144:CB+pgUvZWI8PwF4mjQ1lAMoYiYedzaxHSfDLHl:CgXZWjmmAmiYoaduPF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: John T. Haller
InternalName: KeePass Portable
FileVersion: 1.5.3.0
CompanyName: PortableApps.com
LegalTrademarks: PortableApps.com is a Trademark of Rare Ideas, LLC.
Comments: Allows KeePass to be run from a removable drive. For additional details, visit PortableApps.com/KeePassPortable
ProductName: KeePass Portable
ProductVersion: 1.5.3.0
FileDescription: KeePass Portable
OriginalFilename: KeePassPortable.exe
Translation: 0x0409 0x04b0

Trojan.RanSerKD.4048950 also known as:

BkavW32.PairtaxinAP.Trojan
K7AntiVirusTrojan ( 005011fe1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Genasom
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
ZillyaTrojan.Cerber.Win32.149
SangforRansom.Win32.Cerber.mt
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.bab03b7a
K7GWTrojan ( 005011fe1 )
Cybereasonmalicious.ddb973
CyrenW32/Filecoder.NULU-6387
SymantecRansom.Cryptodefense
ESET-NOD32Win32/Filecoder.Cerber.E
ZonerTrojan.Win32.52147
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-5435693-0
KasperskyTrojan-Ransom.Win32.Zerber.avxs
BitDefenderTrojan.RanSerKD.4048950
NANO-AntivirusTrojan.Win32.Zerber.eolcpi
ViRobotTrojan.Win32.S.Cerber.306878.A
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanTrojan.RanSerKD.4048950
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.RanSerKD.4048950
SophosMal/Generic-R + Mal/Cerber-AA
ComodoMalware@#3h9xukmixnj0b
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.F116LR
McAfee-GW-EditionBehavesLike.Win32.Browser.dc
FireEyeGeneric.mg.1dec2acddb9734e6
EmsisoftTrojan.RanSerKD.4048950 (B)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
AviraTR/AD.NsisInject.hvkng
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.RanSerKD.D3DC836
AegisLabTrojan.Win32.Zerber.4!c
GDataWin32.Trojan.Agent.OKYTXD
TACHYONRansom/W32.Cerber.306878
AhnLab-V3Trojan/Win32.Cerber.R192363
McAfeeGeneric.aaf
MAXmalware (ai score=100)
VBA32Hoax.Zerber
MalwarebytesRansom.Cerber.Generic
PandaTrj/WLT.C
TrendMicro-HouseCallRansom_CERBER.F116LR
RisingTrojan.Win32.Zerber.j!0.18E5EA (KTSE)
YandexTrojan.Agent.Gen.BHK
IkarusTrojan.Win32.Filecoder
FortinetW32/Injector.OV!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Ransom.Cerber.HyoDINsA

How to remove Trojan.RanSerKD.4048950?

Trojan.RanSerKD.4048950 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment