Ransom

Ransom.Cerber.419 (B) (file analysis)

Malware Removal

The Ransom.Cerber.419 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.419 (B) virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ransom.Cerber.419 (B)?


File Info:

crc32: 30FB2EAB
md5: d25bf7ad6906b9b97a13282eea9eebea
name: D25BF7AD6906B9B97A13282EEA9EEBEA.mlw
sha1: 06f8bc5e6d83df6d3737345058aaef498b431266
sha256: 4de52a4206cebfcaaf22446c8f58bac8ba8d2d75412410c76697c0176878acd2
sha512: 8479121a0ebf7b4a0b9febbf9d45f42b05c099d86e38192145da1bd00b5ca4dd75859a032fcbef3abf6d1994e8636403ce153259bab02767b5fea4a35cd0222f
ssdeep: 6144:1RAFg9h6sCe+EuGhLGMe+DoNbd4oaKz87XQeQ7ke3faOc98Na3LbN9M:AFg98sC0uGhLGMGx7rPrcWYbw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Cerber.419 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10263
MicroWorld-eScanGen:Variant.Ransom.Cerber.419
CAT-QuickHealRansom.Cerber.C5
McAfeeRansomware-FLFJ!D25BF7AD6906
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00504a281 )
BitDefenderGen:Variant.Ransom.Cerber.419
K7GWTrojan ( 00504a281 )
Cybereasonmalicious.d6906b
BitDefenderThetaGen:NN.ZexaF.34590.LqX@aiD5gyh
CyrenW32/S-cf90acd9!Eldorado
SymantecRansom.Cerber!g18
TrendMicro-HouseCallRansom_CERBER.F117BH
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.0efa2729
NANO-AntivirusTrojan.Win32.Zerber.elpbxg
RisingRansom.Cerber!8.3058 (CLOUD)
Ad-AwareGen:Variant.Ransom.Cerber.419
EmsisoftGen:Variant.Ransom.Cerber.419 (B)
ComodoTrojWare.Win32.TrojanProxy.Bunitu.BM@6wwq49
F-SecureHeuristic.HEUR/AGEN.1128763
ZillyaTrojan.Zerber.Win32.972
TrendMicroRansom_CERBER.F117BH
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hh
FireEyeGeneric.mg.d25bf7ad6906b9b9
SophosML/PE-A + Mal/CerberW-A
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Zerber.asf
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1128763
Antiy-AVLTrojan[Ransom]/Win32.Zerber
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Ransom.Cerber.419
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Cerber.419
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.R195092
Acronissuspicious
VBA32BScope.TrojanRansom.Cerber
ALYacGen:Variant.Ransom.Cerber.419
MAXmalware (ai score=86)
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32Win32/Filecoder.Cerber.G
TencentMalware.Win32.Gencirc.10ba76fa
YandexTrojan.GenAsa!YEiVbjN6cvM
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Cerber.G!tr.ransom
WebrootW32.Ransom.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.21a

How to remove Ransom.Cerber.419 (B)?

Ransom.Cerber.419 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment