Ransom

Generic.Ransom.Cerber.3D794046 (file analysis)

Malware Removal

The Generic.Ransom.Cerber.3D794046 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Cerber.3D794046 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The executable is likely packed with VMProtect
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Generic.Ransom.Cerber.3D794046?


File Info:

crc32: 4FBD7A85
md5: b20e6998edb0d7d4777e285f3bfea051
name: B20E6998EDB0D7D4777E285F3BFEA051.mlw
sha1: f61d1365f97360c7b63094147fdbbcee79976440
sha256: f4dbf5414ec7b45756b5e267662524611c626d3df48fe959d2bd95a3bed132e6
sha512: 8b2f10e285bf251c695a0439824090c9be9a48ce1afafd1cf74b51cedaac686cfbdcdee1422bc6092bc431e2c3585fdbfd94593606bb0030a881023cef3930d2
ssdeep: 3072:WLvIesoTRaq4TUsIY0WVKpNRWWjl7aH2DiadGKf0Wpfz6EkdOT:WL3YqYUsnmHWyM2D9dFs8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Meloe Khoums
InternalName: unturbidly
FileVersion: 8.10.0.0
CompanyName: Meloe Khoums
ProductName: unturbidly empt
ProductVersion: 8.10.0.0
FileDescription: unturbidly glew sexes
OriginalFilename: unturbidly.exe
Translation: 0x0409 0x04b0

Generic.Ransom.Cerber.3D794046 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f1bd11 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4794
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.Cerber.3D794046
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1308847
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Cerber.93482e83
K7GWTrojan ( 004f1bd11 )
Cybereasonmalicious.8edb0d
CyrenW32/S-aaa71941!Eldorado
SymantecRansom.Cerber
ESET-NOD32a variant of Win32/Kryptik.EZUD
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Cerber-7465035-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Cerber.3D794046
NANO-AntivirusTrojan.Win32.Encoder.evqdym
MicroWorld-eScanDeepScan:Generic.Ransom.Cerber.3D794046
TencentWin32.Trojan.Generic.Pbfa
Ad-AwareDeepScan:Generic.Ransom.Cerber.3D794046
SophosMal/Generic-S
ComodoMalware@#3liai0aogw6h9
BitDefenderThetaGen:NN.ZexaF.34142.iu0@aG!2Ygoi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.cvg
FireEyeGeneric.mg.b20e6998edb0d7d4
EmsisoftDeepScan:Generic.Ransom.Cerber.3D794046 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Zerber.mz
AviraHEUR/AGEN.1121409
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1954095
MicrosoftRansom:Win32/Cerber.A
ArcabitDeepScan:Generic.Ransom.Cerber.3D794046
GDataDeepScan:Generic.Ransom.Cerber.3D794046
AhnLab-V3Trojan/Win32.Cerber.C1476719
McAfeeGeneric.cvg
MAXmalware (ai score=98)
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:r91QIIUgBz+O6gRy935U5A)
YandexTrojan.Agent!Hf1zCzJp9e8
IkarusTrojan.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Cerber.3D794046?

Generic.Ransom.Cerber.3D794046 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment