Ransom

Ransom.Cerber.545 removal

Malware Removal

The Ransom.Cerber.545 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.545 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Ransom.Cerber.545?


File Info:

crc32: 0DC35535
md5: 0675e6225004c7c4d59c7edc25c9717c
name: 0675E6225004C7C4D59C7EDC25C9717C.mlw
sha1: 5ba7ecf77aaa0d66f227e52d1efcceebdf1e4b91
sha256: 8fb4d5340b5c07ffd68dc69ceb7ec91b241bf8b7fe43095026ceee9cddd74e86
sha512: 933e9dc9969e74aa1143f0066b6d4b86192d7b88dc407501c8d390a1febb5ace3af2cefe3a6271236a3edaa70aa7f92719468fb1a01eaae6ecea86e4116ff6f8
ssdeep: 12288:hBE4YM8Se72yHS4Yn5cuxqx8pstId6ic/Dl6q:E4YM8Ip4Nuxquj6p
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom.Cerber.545 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005190011 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.13570
ClamAVWin.Trojan.Tofsee-6345150-0
McAfeeRansomware-GHE!0675E6225004
CylanceUnsafe
ZillyaTrojan.Cryptor.Win32.193
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Locky.00028efa
K7GWTrojan ( 005190011 )
Cybereasonmalicious.25004c
CyrenW32/Locky.CN.gen!Eldorado
SymantecRansom.Locky.B
ESET-NOD32a variant of Win32/Kryptik.FXHJ
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Locky.afho
BitDefenderGen:Variant.Ransom.Cerber.545
NANO-AntivirusTrojan.Win32.Filecoder.etgsul
MicroWorld-eScanGen:Variant.Ransom.Cerber.545
TencentMalware.Win32.Gencirc.11493315
Ad-AwareGen:Variant.Ransom.Cerber.545
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Ransom.Locky.AI@7abtf8
BitDefenderThetaGen:NN.ZexaF.34678.JqW@aiBZyWn
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hc
FireEyeGeneric.mg.0675e6225004c7c4
EmsisoftGen:Variant.Ransom.Cerber.545 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Poison.awe
AviraHEUR/AGEN.1120889
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Locky.A
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Trojan.Kryptik.IH
AhnLab-V3Win-Trojan/RansomCrypt.Exp
Acronissuspicious
VBA32Trojan.FakeAV.01657
MAXmalware (ai score=100)
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMALY0
RisingRansom.Locky!8.1CD4 (C64:YzY0Oj+4+wHRAi14)
IkarusTrojan-Ransom.Locky
FortinetW32/GenKryptik.DKMH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Locky.HxQBEpsA

How to remove Ransom.Cerber.545?

Ransom.Cerber.545 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment