Ransom

Ransom.Cerbu.29 (B) malicious file

Malware Removal

The Ransom.Cerbu.29 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerbu.29 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom.Cerbu.29 (B)?


File Info:

name: 9E8D485D21C2BBCCC78C.mlw
path: /opt/CAPEv2/storage/binaries/b00057dd8ca96a9ab534720692adfc912539f2b818ecc73714d2ba35ca98b54e
crc32: 349ED851
md5: 9e8d485d21c2bbccc78cdeaf14287905
sha1: ad2e1381f5f976cc61416ba3bd71a36ff8032c77
sha256: b00057dd8ca96a9ab534720692adfc912539f2b818ecc73714d2ba35ca98b54e
sha512: cbcbb09272850305719c6e4cabddc33288b1095f0dca3fd2bfc52e5eb77655c9c108877efe173aca14c43ccdc04f9426cf5e2423dd1b80f1d21fe584c506ab3b
ssdeep: 3072:GcORFUxlnjmDXokC+GfHYToSM4ryTv8GjLo2mdISwMpdCq/IM8uIGfN/ODsCp:GvsZjgXo7gTt3ryT0OoISwMd7wvcU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128346B02F66CFCFDD41980300876C6F21A39FC3266A0955FB7E57F1A1D71293B91AA26
sha3_384: f76daed08c607257680edc2438776ba6a9060370d3563d38ff5e3b1ca36195cc46549b92f7444a8f8773358b56c99967
ep_bytes:
timestamp: 2002-07-24 15:15:53

Version Info:

0: [No Data]

Ransom.Cerbu.29 (B) also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Ransom.Cerbu.29
FireEyeGeneric.mg.9e8d485d21c2bbcc
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Damaged_File.E.gen!Eldorado
APEXMalicious
ClamAVWin.Trojan.Shodi-4
BitDefenderGen:Variant.Ransom.Cerbu.29
AvastWin32:Trojan-gen
EmsisoftGen:Variant.Ransom.Cerbu.29 (B)
ComodoHeur.Corrupt.PE@1z141z3
DrWebProgram.RemoteAdmin
SophosGeneric ML PUA (PUA)
Antiy-AVLRiskWare[RemoteAdmin]/Win32.RAdmin
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Ransom.Cerbu.29
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Cerbu.29
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.R03BH09B122
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Application
AVGWin32:Trojan-gen
Cybereasonmalicious.1f5f97

How to remove Ransom.Cerbu.29 (B)?

Ransom.Cerbu.29 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment