Ransom

Should I remove “Ransom.Cerber.324”?

Malware Removal

The Ransom.Cerber.324 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.324 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Cerber ransomware
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ransom.Cerber.324?


File Info:

crc32: EF72CD7C
md5: 7a4d63dd273b65a251d32db9c00571ed
name: upload_file
sha1: 118042a1491dcd69ca911c521cf0742da090a63e
sha256: f540851ddbe177871c4b65f11a10bc1c047253d7de4bcda89918de821eac3b8b
sha512: f842c037df0a41d7e73208268cb29ea3bf7c1ffd9a3c9d3b283a23eb427e215b8fb37035594fd2c4f985ea1ba417dc8963f36d877bd6f7f88f5c217a1f2e592e
ssdeep: 6144:EvHLtLMCHg3FxbyypAlFy1BWfc3xhacB58A22LU1Z2B0lrTs4Hybar:EfLhMCHgVx2ypgFy1BWfyEL2vOTsCr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Cerber.324 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Cerber.324
FireEyeGeneric.mg.7a4d63dd273b65a2
CAT-QuickHealRansom.Crysis.A5
Qihoo-360HEUR/QVM10.1.A3A3.Malware.Gen
McAfeeRansomware-FLTU!7A4D63DD273B
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.1279
K7AntiVirusTrojan ( 0050432d1 )
BitDefenderGen:Variant.Ransom.Cerber.324
K7GWTrojan ( 0050432d1 )
CrowdStrikewin/malicious_confidence_100% (D)
TrendMicroRansom_HPLOCKY.SM4
SymantecRansom.Cerber!g17
APEXMalicious
KasperskyTrojan-Ransom.Win32.Zerber.bruy
NANO-AntivirusTrojan.Win32.Zerber.elgyef
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
Ad-AwareGen:Variant.Ransom.Cerber.324
SophosMal/Cerber-V
ComodoTrojWare.Win32.Ransom.Cerber.DW@7f7w7c
F-SecureHeuristic.HEUR/AGEN.1127095
DrWebTrojan.PWS.Panda.11620
InvinceaMal/Cerber-V
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftGen:Variant.Ransom.Cerber.324 (B)
SentinelOneDFI – Malicious PE
JiangminTrojan.Zerber.aos
AviraHEUR/AGEN.1127095
MAXmalware (ai score=80)
Antiy-AVLTrojan[Ransom]/Win32.Zerber
MicrosoftTrojan:Win32/CryptInject!ml
ArcabitTrojan.Ransom.Cerber.324
ZoneAlarmTrojan-Ransom.Win32.Zerber.bruy
GDataGen:Variant.Ransom.Cerber.324
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zerber.C1783520
BitDefenderThetaGen:NN.ZexaF.34570.wuZ@aixv3@bm
ALYacGen:Variant.Ransom.Cerber.324
VBA32TrojanRansom.Zerber
ESET-NOD32a variant of Win32/Injector.DKQB
TrendMicro-HouseCallRansom_HPLOCKY.SM4
TencentMalware.Win32.Gencirc.10bc44f9
YandexTrojan.Zerber!
IkarusTrojan.Win32.Filecoder
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.DILW!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.d273b6
AvastWin32:Trojan-gen

How to remove Ransom.Cerber.324?

Ransom.Cerber.324 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment