Ransom

Ransom.Cerber.A3 removal guide

Malware Removal

The Ransom.Cerber.A3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.A3 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ransom.Cerber.A3?


File Info:

crc32: 47522A31
md5: 70aa95022d5e359322411a91bffd0bf5
name: 70AA95022D5E359322411A91BFFD0BF5.mlw
sha1: 1fe9891dfb2d311e46f71542765b6c1f9253cd0c
sha256: 20b9ff24148baa96dbe1a0a7a48bbbeada81598988ee10605ebb21b139359e09
sha512: 9719da432e47aa2d1f5b19078a890354aaef5d9a384d579f8cee969fa20a7ed2dc503af8f9b94dbe8af73ff715f3ee2c7404f4fde5702e32450ba275c8369482
ssdeep: 6144:yffffhXXXXmjOXB/aReDs7Fcqoj+g9kH1Ie/pYe:TKR/SJKN19j+Ye
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Idleheaded2
FileVersion: 1.00
CompanyName: @
ProductName: Rethresher
ProductVersion: 1.00
OriginalFilename: Idleheaded2.exe

Ransom.Cerber.A3 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A3
ALYacTrojan.CryptoLocker.EL
CylanceUnsafe
ZillyaTrojan.SelfDel.Win32.53613
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.ffa328cf
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.22d5e3
CyrenW32/Cerber.I.gen!Eldorado
SymantecRansom.Cerber!g6
ESET-NOD32Win32/Filecoder.Cerber.B
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Cryptolocker-6984452-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.CryptoLocker.EL
NANO-AntivirusTrojan.Win32.Encoder.ecxhjf
MicroWorld-eScanTrojan.CryptoLocker.EL
TencentMalware.Win32.Gencirc.10b9b5b4
Ad-AwareTrojan.CryptoLocker.EL
SophosML/PE-A + Troj/Agent-ARZB
ComodoMalware@#2bgv1zgj1a87s
BitDefenderThetaGen:NN.ZevbaF.34790.mm1@aurAz6ni
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_FAREIT.SMEJ
McAfee-GW-EditionFareit-FEL!70AA95022D5E
FireEyeGeneric.mg.70aa95022d5e3593
EmsisoftTrojan.CryptoLocker.EL (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfdel.cbz
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1130107
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.18ECB46
MicrosoftRansom:Win32/Cerber
GDataTrojan.CryptoLocker.EL
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeeFareit-FEL!70AA95022D5E
MAXmalware (ai score=100)
VBA32Trojan.SelfDel
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_FAREIT.SMEJ
YandexTrojan.SelfDel!ZfIgMhWqFQo
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CZOJ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Worm.CryptoLock.HgIASOkA

How to remove Ransom.Cerber.A3?

Ransom.Cerber.A3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment