Ransom

Generic.Ransom.Cerber.35F70EA8 removal guide

Malware Removal

The Generic.Ransom.Cerber.35F70EA8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Cerber.35F70EA8 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipinfo.io

How to determine Generic.Ransom.Cerber.35F70EA8?


File Info:

crc32: B99D8D1D
md5: bdeb769d25acfc8adb41a3b8b35feb9c
name: BDEB769D25ACFC8ADB41A3B8B35FEB9C.mlw
sha1: 9f524fc4509c9838a5a42d7da2775f6840d6cbf2
sha256: 31890b6c5cc4c1a1546cabe854b25f429a27c0a4b7208fb6b49735c58a1b085e
sha512: b17b72a456ee4079d0464b83e757ea760fb519344d0c3f67be352db9e7a886ed68d3d5d218eb17c2295cebb1fd6be25871a2518386cc7956d96ebef1e970ffeb
ssdeep: 3072:tEUNbXAVoO5Afv1ddfCPDNmK6qd+CnBxTIYIy9hAlCUqwtBOd:6HAfv1d1EDNmad5wYd3pUqw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Von Lpw
InternalName: polewig
FileVersion: 4.7
CompanyName: Von Lpw
ProductName: polewig ihp plumb
ProductVersion: 4.7
FileDescription: polewig pulk tun
OriginalFilename: polewig.exe
Translation: 0x0409 0x04b0

Generic.Ransom.Cerber.35F70EA8 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051cfe21 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.Cerber.35F70EA8
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.21046102
K7GWTrojan ( 0051cfe21 )
Cybereasonmalicious.d25acf
ESET-NOD32a variant of Win32/Kryptik.EZQC
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Cerber.35F70EA8
NANO-AntivirusTrojan.Win32.Cerber.evmucb
MicroWorld-eScanDeepScan:Generic.Ransom.Cerber.35F70EA8
TencentWin32.Trojan.Generic.Pkrb
Ad-AwareDeepScan:Generic.Ransom.Cerber.35F70EA8
SophosML/PE-A + Mal/Cerber-C
ComodoMalware@#388zok4xxzr29
BitDefenderThetaGen:NN.ZexaF.34142.iq0@aOvy@wii
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.bdeb769d25acfc8a
EmsisoftDeepScan:Generic.Ransom.Cerber.35F70EA8 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bsugi
AviraHEUR/AGEN.1113895
Antiy-AVLTrojan/Generic.ASMalwS.22DCEDB
MicrosoftTrojan:Win32/Tiggre!rfn
GDataDeepScan:Generic.Ransom.Cerber.35F70EA8
Acronissuspicious
McAfeeRansomware-GIX!BDEB769D25AC
MAXmalware (ai score=89)
VBA32BScope.TrojanPSW.Papras
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:3uTbS4yYjLLrPCdr0+E6FA)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.FBWY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Cerber.35F70EA8?

Generic.Ransom.Cerber.35F70EA8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment