Ransom

How to remove “Ransom.Cerber.171 (B)”?

Malware Removal

The Ransom.Cerber.171 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.171 (B) virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates known PcClient mutex and/or file changes.

How to determine Ransom.Cerber.171 (B)?


File Info:

crc32: D5A69EEE
md5: 7861dbaa2eea355f6aa12c891d725e81
name: 7861DBAA2EEA355F6AA12C891D725E81.mlw
sha1: 4506e43f9ecaa1b894192a05bcffac1f8505e1fe
sha256: edf0de65218e8eda5a259f8ad7d87b38bd1f83a3c998d6121534e125b5252b9c
sha512: 371b02840cf71b90368c14ba8b21508b5520ab0ab2ea785bdd3b703a3c9364dde62482330e77e5e90b9053117e0e9f4fc1ee348c3800eab42145b47217015e7c
ssdeep: 6144:1k2F4115j5Pvaxv5JTPm1xgEg4EgB/guR4PcyKda:4115j5X2OjgvgRgsdyKda
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Cerber.171 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop16.30764
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Cerber.171
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/OnlineGames.BW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Dialer.NEW
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Trojan.Farfli-9754465-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Cerber.171
MicroWorld-eScanGen:Variant.Ransom.Cerber.171
Ad-AwareGen:Variant.Ransom.Cerber.171
SophosML/PE-A + Mal/Redos-H
F-SecureBackdoor.BDS/Backdoor.Gen
BitDefenderThetaAI:Packer.4B38C8D01F
VIPRETrojan.Win32.Redosdru.C (v)
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dh
FireEyeGeneric.mg.7861dbaa2eea355f
EmsisoftGen:Variant.Ransom.Cerber.171 (B)
SentinelOneStatic AI – Malicious PE
JiangminHeur:Trojan/KillAV
AviraBDS/Backdoor.Gen
eGambitTrojan.Generic
MicrosoftBackdoor:Win32/PcClient.ZR
ArcabitTrojan.Ransom.Cerber.171
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Cerber.171
AhnLab-V3Malware/Win32.RL_Generic.R358321
Acronissuspicious
McAfeeArtemis!7861DBAA2EEA
MAXmalware (ai score=81)
VBA32BScope.Trojan.SvcHorse.01643
MalwarebytesMalware.AI.2866956524
RisingBackdoor.Farfli!1.6495 (CLOUD)
IkarusTrojan.Win32.Agent
FortinetW32/Dialer.NEW
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.PcClient.HgIASQkA

How to remove Ransom.Cerber.171 (B)?

Ransom.Cerber.171 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment