Ransom

How to remove “Ransom.Cerber.497”?

Malware Removal

The Ransom.Cerber.497 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.497 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system

How to determine Ransom.Cerber.497?


File Info:

crc32: 3EC6FF0C
md5: 58b23046382f895eacf9daa0b5330bee
name: 58B23046382F895EACF9DAA0B5330BEE.mlw
sha1: ea5907dfd4cb3d09e0b6a49fdde0a38654d9ad8d
sha256: 5bd2e252b7b318e082cb2c695bb98fdc001d24e9667d6d8da2f4779eb076f345
sha512: 212a97cba2fe09e98901074534c071c8f6f6a15ba61f347c99c1b4b0e86235eab460faf8cb761e0897525c458800cf42ea922230ddc8410ee757fd50a4a785d8
ssdeep: 6144:eoKECN75BnN60z2Jwk90CFLGjml+muGwNjdg6G6OTvKI:Dzo75+0pk90C5+ml+KwNJg6G6M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

XXXXXXXXXXXXXXXXXX: ?,x01FileDescription
XXXX: |,x01LegalCopyright
FileVersion: 2.0.6.0
CompanyName: TechSmith Corporation
yright (C) 2005 TechSmith Corporation: X
hSmith Screen Capture Codec onstaller: X
Translation: 0x0409 0x04e4

Ransom.Cerber.497 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10201
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A4
ALYacGen:Variant.Ransom.Cerber.497
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1013644
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Cerber.ali1020013
K7GWTrojan ( 005021361 )
Cybereasonmalicious.6382f8
BaiduWin32.Trojan.Kryptik.ayf
CyrenW32/S-3e1d46f2!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FMQF
APEXMalicious
AvastWin32:Filecoder-BG [Trj]
ClamAVWin.Ransomware.Cerber-5970079-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Cerber.497
NANO-AntivirusTrojan.Win32.Zerber.eljpah
MicroWorld-eScanGen:Variant.Ransom.Cerber.497
TencentMalware.Win32.Gencirc.10b56d24
Ad-AwareGen:Variant.Ransom.Cerber.497
SophosML/PE-A + Mal/Cerber-B
ComodoTrojWare.Win32.Ransom.Cerber.BF@6tebck
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionBehavesLike.Win32.Ransomware.gh
FireEyeGeneric.mg.58b23046382f895e
EmsisoftGen:Variant.Ransom.Cerber.497 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gfqev
AviraHEUR/AGEN.1106595
eGambitUnsafe.AI_Score_94%
MicrosoftRansom:Win32/Cerber!rfn
AegisLabTrojan.Win32.Zerber.j!c
GDataGen:Variant.Ransom.Cerber.497
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-CBER!58B23046382F
MAXmalware (ai score=82)
VBA32Hoax.Zerber
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
RisingTrojan.Kryptik!1.A877 (CLOUD)
YandexTrojan.GenAsa!cSw+33hI+sA
IkarusTrojan.Ransom.Cerber
FortinetW32/Injector.EETM!tr
AVGWin32:Filecoder-BG [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HxQBEpsA

How to remove Ransom.Cerber.497?

Ransom.Cerber.497 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment