Ransom

Should I remove “Ransom.Cerber.461”?

Malware Removal

The Ransom.Cerber.461 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.461 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Cerber.461?


File Info:

crc32: 0DB3072B
md5: cb8742408c4c6aff21bd3ec08bd7549a
name: CB8742408C4C6AFF21BD3EC08BD7549A.mlw
sha1: 834dda1e73ea9588aee9f8ff3cd99c87806ea907
sha256: 896f0840e292986e54c51a4e6182b9f3f3df73860bcb5ca0161e1b7ffce9113b
sha512: 41988dc13457e7ff16c2082a441adff67470077b6d4fc5791ee1ad3aa798202815ec98e17f54acf756118238c3de305f3d4608d456126e5f0d1106201b85e076
ssdeep: 3072:wA7A7zA7WdYtDrJwD9kqQKqQTT5QdRmCtV5rtrqcvxk5doCc82ba5Dm2vBEHyx3:2mGoiKdUCLNxqcwabapRpU4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Cerber.461 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005190011 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.A4
ALYacGen:Variant.Ransom.Cerber.461
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.3054
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0051097b1 )
Cybereasonmalicious.08c4c6
CyrenW32/S-063e4d81!Eldorado
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FTSU
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Cerber.461
NANO-AntivirusTrojan.Win32.Zerber.eqpcbd
ViRobotTrojan.Win32.U.Cerber.237568
MicroWorld-eScanGen:Variant.Ransom.Cerber.461
TencentTrojan.Win32.Cerber.h
Ad-AwareGen:Variant.Ransom.Cerber.461
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Crypt.C@7vajd0
BitDefenderThetaGen:NN.ZexaF.34670.oqW@au4MlKji
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SM3B
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
FireEyeGeneric.mg.cb8742408c4c6aff
EmsisoftGen:Variant.Ransom.Cerber.461 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.cri
AviraHEUR/AGEN.1105007
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Ransom.Cerber.461
AegisLabTrojan.Win32.Zerber.j!c
GDataGen:Variant.Ransom.Cerber.461
AhnLab-V3Trojan/Win32.Cerber.R203165
Acronissuspicious
McAfeeRansomware-GBX!CB8742408C4C
MAXmalware (ai score=86)
VBA32Hoax.Zerber
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CERBER.SM3B
RisingTrojan.Kryptik!1.ABBF (CLOUD)
YandexTrojan.GenAsa!m9XVdzAct3k
IkarusTrojan-Ransom.Cerber
FortinetW32/Agent.CIXD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQBqqsA

How to remove Ransom.Cerber.461?

Ransom.Cerber.461 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment