Categories: Ransom

Ransom:Win32/Cerber.F information

The Ransom:Win32/Cerber.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Cerber.F virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Cerber ransomware
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ransom:Win32/Cerber.F?


File Info:

crc32: 754C361Bmd5: df4ab81b67ccfbde82ce0d87953be5d9name: DF4AB81B67CCFBDE82CE0D87953BE5D9.mlwsha1: c21a7258a73dfdc051a8458d1dda41ccfa60d544sha256: 679684697ee06a22c48b9ffa98fc4aa76ebec4ca1433b21ae19e0c7f8a5eeab3sha512: 2fcb4c19bc3c5fe1371906e370dfe50036a17f2cb1f1df396a73f3fa4191ef176b4c537080624fb2846960aaeca91242290bc64b154046957cceb0b12e895cc3ssdeep: 6144:xzed1xAVVSnn/lm2IGh+ASR3mW/ALal6x:xzed1xAmn/1xZU2WoLal+type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

XXXXXXXXXXXXXXXXXX: ?,x01FileDescriptionXXXX: |,x01LegalCopyrightFileVersion: 2.0.6.0CompanyName: TechSmith Corporationyright (C) 2005 TechSmith Corporation: XhSmith Screen Capture Codec 33333ller: XTranslation: 0x0409 0x04e4

Ransom:Win32/Cerber.F also known as:

Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Ransom.Cerber.1
FireEye Generic.mg.df4ab81b67ccfbde
CAT-QuickHeal TrojanRansom.Crowti.MUE.A4
ALYac Trojan.Ransom.Cerber.1
Cylance Unsafe
Sangfor Malware
K7AntiVirus Trojan ( 005224381 )
BitDefender Trojan.Ransom.Cerber.1
K7GW Trojan ( 004fcba41 )
Cybereason malicious.b67ccf
TrendMicro Ransom_CERBER.SMEJ7
Cyren W32/Trojan.UO.gen!Eldorado
Symantec Packed.Generic.459
Baidu Win32.Trojan.Kryptik.ayf
APEX Malicious
Avast Win32:Evo-gen [Susp]
ClamAV Win.Ransomware.Cerber-7460267-0
Kaspersky Trojan.Win32.Menti.gen
NANO-Antivirus Trojan.Win32.Zerber.erbcfw
Tencent Malware.Win32.Gencirc.10b4af84
Ad-Aware Trojan.Ransom.Cerber.1
Emsisoft Trojan.Ransom.Cerber.1 (B)
Comodo TrojWare.Win32.Ransom.Cerber.BS@6s12k8
F-Secure Trojan.TR/Crypt.XPACK.Gen7
DrWeb Trojan.Encoder.7074
Invincea ML/PE-A + Mal/Cerber-B
McAfee-GW-Edition BehavesLike.Win32.VirRansom.fh
Sophos Mal/Cerber-B
Ikarus Trojan.Crypt
Avira TR/Crypt.XPACK.Gen7
Microsoft Ransom:Win32/Cerber.F
Arcabit Trojan.Ransom.Cerber.1
AhnLab-V3 Win-Trojan/Cerber.Gen
ZoneAlarm Trojan.Win32.Menti.gen
GData Trojan.Ransom.Cerber.1
Cynet Malicious (score: 100)
ESET-NOD32 a variant of Win32/Kryptik.FJKV
Acronis suspicious
McAfee GenericRXAP-FP!DF4AB81B67CC
MAX malware (ai score=86)
VBA32 BScope.Trojan.Crypt
Malwarebytes Ransom.Cerber
Panda Trj/Genetic.gen
TrendMicro-HouseCall Ransom_CERBER.SMEJ7
Rising Ransom.Cerber!8.3058 (TFE:3:Bj9TfT5gGHD)
Yandex Trojan.GenAsa!UO7cg0d6lkQ
SentinelOne Static AI – Malicious PE
eGambit Unsafe.AI_Score_58%
Fortinet W32/Kryptik.HGZD!tr
Webroot W32.Trojan.Gen
AVG FileRepMalware
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM20.1.455B.Malware.Gen

How to remove Ransom:Win32/Cerber.F?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.641344743 (file analysis)

The Malware.AI.641344743 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

Malware.AI.2427035797 removal

The Malware.AI.2427035797 is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

Win32/AutoRun.VB.TP removal instruction

The Win32/AutoRun.VB.TP is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

Trojan.MauvaiseRI.S5242943 information

The Trojan.MauvaiseRI.S5242943 is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

Zusy.297198 (B) information

The Zusy.297198 (B) is considered dangerous by lots of security experts. When this infection is…

18 mins ago

Should I remove “Trojan.Win32.Agent.xbnair”?

The Trojan.Win32.Agent.xbnair is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago