Ransom

Should I remove “Generic.Ransom.Cerber.26D8494F”?

Malware Removal

The Generic.Ransom.Cerber.26D8494F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Cerber.26D8494F virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipinfo.io

How to determine Generic.Ransom.Cerber.26D8494F?


File Info:

crc32: 4449A697
md5: b6a5f9cec9f5cd0c2da55ca2a6136c66
name: B6A5F9CEC9F5CD0C2DA55CA2A6136C66.mlw
sha1: 0b60447e7d754e15bf9743d25af6ec38a5c186b4
sha256: 3586f7705f633fbd2d18af612ef1cc2dfc5a192ce8a7e9c31b11cf2317339844
sha512: 14c944b2651842a7431f2cc56d207b4bbeca52cb82d73f81f3f90bfb8d61adab2505ec862bd22828a1cab9b292b5aa8183c1196ee83995deef677593eff13bed
ssdeep: 3072:QTAIiQFjjasuNV50lkbBuAR+FLfW9y/R7nm:QUIilJ0MBPRMfW9yF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Tingler Tps
InternalName: worming
FileVersion: 5.3
CompanyName: Tingler Tps
ProductName: worming phos ned
ProductVersion: 5.3
FileDescription: worming weirdless ipl
OriginalFilename: worming.exe
Translation: 0x0409 0x04b0

Generic.Ransom.Cerber.26D8494F also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f27101 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4794
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.Cerber.26D8494F
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.4073
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f27101 )
Cybereasonmalicious.ec9f5c
SymantecRansom.Cerber!gm
ESET-NOD32a variant of Win32/Kryptik.EZRH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.fgss
BitDefenderDeepScan:Generic.Ransom.Cerber.26D8494F
NANO-AntivirusTrojan.Win32.Zerber.evigel
MicroWorld-eScanDeepScan:Generic.Ransom.Cerber.26D8494F
TencentWin32.Trojan.Zerber.Pgmn
Ad-AwareDeepScan:Generic.Ransom.Cerber.26D8494F
SophosML/PE-A + Mal/Cerber-C
ComodoMalware@#3rlzoqy2d2jom
BitDefenderThetaGen:NN.ZexaF.34104.iq0@ayXC49ji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.b6a5f9cec9f5cd0c
EmsisoftDeepScan:Generic.Ransom.Cerber.26D8494F (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.djn
AviraHEUR/AGEN.1121409
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.22C86BB
MicrosoftRansom:Win32/Avaddon.P!MSR
GDataDeepScan:Generic.Ransom.Cerber.26D8494F
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-GIX!B6A5F9CEC9F5
MAXmalware (ai score=99)
VBA32Trojan-Ransom.Zerber
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:XEU6Xv+weq0VT/kUL8FnjQ)
YandexTrojan.Zerber!/e8kXeQ/rm0
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Cerber.26D8494F?

Generic.Ransom.Cerber.26D8494F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment