Ransom

Ransom.Cerber.311 removal

Malware Removal

The Ransom.Cerber.311 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.311 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Cerber ransomware
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system

How to determine Ransom.Cerber.311?


File Info:

crc32: 6FBDD5A4
md5: de613c5fa30e8983fec492f2d63b7022
name: DE613C5FA30E8983FEC492F2D63B7022.mlw
sha1: ec2a456bcfeca2ab4af19b3bc43e628db126d9ea
sha256: f258bada5a08c91ffe9175ba72e75777a46a7eac9b640e9730314e5d282c441e
sha512: 4622d70663c64ceaa6caebe0231d528489b5825af9032ac3d1ce7c77f1dbd07a0cbaee1e0ef1f303c482d5dd31d22d3310110205bf017404a05587211f13cc9e
ssdeep: 6144:FBFsyMJ57tNGldcww4N9rpWmOa0XtyldUHb+wVl191viW5rwAdVVoyiZz:JMJYlPNW7FdEU33sW5rihl
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: zzefzjoizoef.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: zzefzjoizoef.exe
Translation: 0x040c 0x04b0

Ransom.Cerber.311 also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10697
MicroWorld-eScanGen:Variant.Ransom.Cerber.311
FireEyeGeneric.mg.de613c5fa30e8983
CAT-QuickHealRansom.Crysis.A5
Qihoo-360HEUR/QVM11.1.88FD.Malware.Gen
ALYacGen:Variant.Ransom.Cerber.311
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.GenericKD.4783464
K7AntiVirusTrojan ( 0050ae2f1 )
BitDefenderGen:Variant.Ransom.Cerber.311
K7GWTrojan ( 0050ae2f1 )
Cybereasonmalicious.fa30e8
BitDefenderThetaGen:NN.ZexaF.34590.xmNfaG8Lxgfm
CyrenW32/Cerber.JYYV-9300
SymantecRansom.Cerber!g34
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-7343764-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Agent.ennujc
RisingRansom.Cerber!8.3058 (RDMK:cmRtazp7/4j7Qi7TXB+akiBB6BGF)
Ad-AwareGen:Variant.Ransom.Cerber.311
SophosML/PE-A + Mal/Cerber-AB
F-SecureHeuristic.HEUR/AGEN.1120931
ZillyaTrojan.Injector.Win32.494113
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fc
EmsisoftGen:Variant.Ransom.Cerber.311 (B)
IkarusTrojan.Win32.Injector
JiangminTrojan.Zerber.bjx
AviraHEUR/AGEN.1120931
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Cerber.J
ArcabitTrojan.Ransom.Cerber.311
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Cerber.311
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRansomware-FMEE!DE613C5FA30E
VBA32BScope.Trojan.Inject
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win32/Injector.DNPD
TencentMalware.Win32.Gencirc.10bb7700
YandexTrojan.GenAsa!uONQGDeDk8A
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AP.B6F58!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Ransom.Cerber.311?

Ransom.Cerber.311 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment