Trojan

About “Trojan:Win32/Ketrican!ic” infection

Malware Removal

The Trojan:Win32/Ketrican!ic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ketrican!ic virus can do?

  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Ketrican!ic?


File Info:

name: CC8882DFD58B69CBC341.mlw
path: /opt/CAPEv2/storage/binaries/a78cc475c1875186dcd1908b55c2eeaf1bcd59dedaff920f262f12a3a9e9bfa8
crc32: A8EAF12A
md5: cc8882dfd58b69cbc341065d29f9c1e9
sha1: c8fbb7c0522a092239ca1eacf7a08e850fbea630
sha256: a78cc475c1875186dcd1908b55c2eeaf1bcd59dedaff920f262f12a3a9e9bfa8
sha512: 1bf6b8bf3a9054ae1cbff5930a10b3917a2ca5dc6d176b106fa76e0fb61af27b3b8233251f20b9bba84b50244ea8827b15cf6b0ff0688a3270bdef69e7498ee1
ssdeep: 1536:3HFKQpJ2TLFbHUfn1eyRwLewhnlwSyvdq1Swza/0cnPBr0N9S4A3705YJHHyUh7:3dCbHCnIyRHCUES8qrJZ02JHHy87
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115E39E2172D0D036E4A715329579EBB15DBEB8320B3090C7B7D81B7E2E603D599393AB
sha3_384: d53896650c84ce652c0134c502140c272242f79a6ff1f3c31582702afe4aa1dd53cf194c1c093a9eece2f2d8c58c3318
ep_bytes: e8a0390000e989feffff8bff558bec83
timestamp: 2022-06-27 03:14:35

Version Info:

0: [No Data]

Trojan:Win32/Ketrican!ic also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Zusy.473843
CAT-QuickHealBackdoor.Ketrican.S30472149
McAfeeRDN/Real Protect-LS
MalwarebytesMalware.AI.2551736388
VIPREGen:Variant.Zusy.473843
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a77b51 )
AlibabaTrojan:Win32/Protect.0f4a6753
K7GWTrojan ( 005a77b51 )
Cybereasonmalicious.0522a0
VirITTrojan.Win32.Genus.RNF
CyrenW32/ABRisk.BYCD-6629
SymantecBackdoor.Graphican
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Graphican.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.473843
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Jflw
EmsisoftGen:Variant.Zusy.473843 (B)
F-SecureTrojan.TR/Agent.amwag
DrWebBackDoor.Siggen2.4520
ZillyaTrojan.Generic.Win32.1761059
TrendMicroBackdoor.Win32.GRAPHICAN.THFBFBC
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.cc8882dfd58b69cb
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Zusy.473843
WebrootW32.Backdoor.Graphican
AviraTR/Agent.amwag
Antiy-AVLTrojan/Win32.Generic
XcitiumMalware@#3fgj5y333e18b
ArcabitTrojan.Zusy.D73AF3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ketrican!ic
GoogleDetected
AhnLab-V3Trojan/Win.RealProtect-LS.C5332482
VBA32Trojan.Real
ALYacBackdoor.Agent.Graphican
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Agent.TV
TrendMicro-HouseCallBackdoor.Win32.GRAPHICAN.THFBFBC
RisingTrojan.Generic@AI.100 (RDML:pj3vj/AoV45y6piqEbhcCA)
IkarusBackdoor.Graphican
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Graphican.A!tr
BitDefenderThetaGen:NN.ZexaF.36318.iqW@auFxuyo
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Ketrican!ic?

Trojan:Win32/Ketrican!ic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment