Ransom Trojan

UDS:Trojan-Ransom.Win32.Encoder.krn removal

Malware Removal

The UDS:Trojan-Ransom.Win32.Encoder.krn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Ransom.Win32.Encoder.krn virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine UDS:Trojan-Ransom.Win32.Encoder.krn?


File Info:

name: B1F862DA68278C6F7C0D.mlw
path: /opt/CAPEv2/storage/binaries/ee49609e038413e1e63d369f6c5fba33fbd28643367e63e78d99c0b5d24113b8
crc32: 32EEFDC7
md5: b1f862da68278c6f7c0d1f6a4b749ac1
sha1: b35e0fc393652a5def2630ae7d30fd45c4fccec6
sha256: ee49609e038413e1e63d369f6c5fba33fbd28643367e63e78d99c0b5d24113b8
sha512: 5ccdc3ccc62785a85261a3200f49ea6142d915deee562f1aa8815e04016b5af3ee5c57ede42e24d1b0476f4889380dd83c6dbf0ffe5874b6642d084f7842f2c3
ssdeep: 98304:zs82AFuZwoPllMWHubXkTZONq0d6NlPf9/iPU2ZJm0xcGkRpQY:w0oP1HOXfZ8bntiZ3m0xcGYp5
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CF463315788096A1C2B61A3701E2C534662F7E1D07E45ABBA3D9F7692E323CD393937C
sha3_384: 2f93c95d42ed77ba84c05f5c95ab165ef2186b39dfaac7b85c6130c2a7e36374a611fec59b5edf3d95856d8e7dbe4e95
ep_bytes: e83f050000e987feffffcccccccccccc
timestamp: 2020-08-08 12:29:54

Version Info:

0: [No Data]

UDS:Trojan-Ransom.Win32.Encoder.krn also known as:

LionicTrojan.Win32.Encoder.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35224181
FireEyeGeneric.mg.b1f862da68278c6f
ALYacTrojan.GenericKD.35224181
MalwarebytesMalware.AI.3845170370
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-Ransom.Win32.Encoder.krn
BitDefenderTrojan.GenericKD.35224181
Ad-AwareTrojan.GenericKD.35224181
SophosGeneric ML PUA (PUA)
DrWebTrojan.KillProc2.14813
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
EmsisoftTrojan.GenericKD.35224181 (B)
ZoneAlarmUDS:Trojan-Ransom.Win32.Encoder.krn
GDataTrojan.GenericKD.35224181
McAfeeArtemis!B1F862DA6827
MAXmalware (ai score=80)
VBA32TrojanRansom.Encoder
SentinelOneStatic AI – Suspicious PE
Cybereasonmalicious.a68278

How to remove UDS:Trojan-Ransom.Win32.Encoder.krn?

UDS:Trojan-Ransom.Win32.Encoder.krn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment