Categories: Ransom

About “Ransom:Win32/Cerber.K” infection

The Ransom:Win32/Cerber.K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Cerber.K virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Generates some ICMP traffic
  • Collects information to fingerprint the system

How to determine Ransom:Win32/Cerber.K?


File Info:

crc32: AC80E00Amd5: fbf04e822cb80c9c30c98d1370461318name: FBF04E822CB80C9C30C98D1370461318.mlwsha1: 281baab52591b64f0382c2afae58085372e27fa2sha256: 18fa8f54d2df6708c2c66ed4e3b1e465e1d7464ede7e2d76bde18bf8f620c3e4sha512: 4652e085ece1c5589072916a31cbae0211a372f2ffa711c012a6ec6b58b17c7812b25f69c76ba612689038068487168abdb62a77ea5aa4cb7b8024f7c3a83189ssdeep: 6144:sW0LY/1WC/Cy7t1DRMQvTwb42eETmRYf5Qbg1tOMYW7AB:oLYsCqy7/RM+TWCRYfWO9Utype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompanyName: Adobe Systems IncorporatedTranslation: 0x0409 0x04b0

Ransom:Win32/Cerber.K also known as:

Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
DrWeb Trojan.Encoder.11198
MicroWorld-eScan Trojan.Agent.CGSF
FireEye Generic.mg.fbf04e822cb80c9c
ALYac Trojan.Agent.CGSF
Cylance Unsafe
Sangfor Malware
K7AntiVirus Trojan ( 0050d5a31 )
BitDefender Trojan.Agent.CGSF
K7GW Trojan ( 0050d5a31 )
CrowdStrike win/malicious_confidence_100% (D)
TrendMicro Ransom_HPCERBER.SMALY5A
BitDefenderTheta AI:Packer.F71BC2331F
Cyren W32/Cerber.F.gen!Eldorado
Symantec Ransom.Cerber
ESET-NOD32 a variant of Win32/Kryptik.FSBZ
TrendMicro-HouseCall Ransom_HPCERBER.SMALY5A
Kaspersky HEUR:Trojan.Win32.Generic
ViRobot Trojan.Win32.Cerber.551424
Tencent Malware.Win32.Gencirc.10b3b62c
Ad-Aware Trojan.Agent.CGSF
Sophos Troj/Agent-AJFK
Comodo TrojWare.Win32.Ransom.Cerber.FTV@75b3ao
F-Secure Heuristic.HEUR/AGEN.1121408
Invincea ML/PE-A + Troj/Agent-AJFK
McAfee-GW-Edition BehavesLike.Win32.BadFile.hm
SentinelOne Static AI – Malicious PE
Emsisoft Trojan.Agent.CGSF (B)
Ikarus Trojan.Agent
Jiangmin Trojan.Generic.aycug
Webroot W32.Malware.gen
Avira HEUR/AGEN.1121408
Antiy-AVL Trojan[Ransom]/Win32.Zerber
Microsoft Ransom:Win32/Cerber.K
Arcabit Trojan.Agent.CGSF
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Trojan.Agent.CGSF
Cynet Malicious (score: 100)
AhnLab-V3 Win-Trojan/Cerber.Exp
McAfee GenericRXAA-AA!FBF04E822CB8
MAX malware (ai score=82)
VBA32 BScope.Backdoor.Vawtrak
Malwarebytes Ransom.Cerber
Panda Trj/Genetic.gen
APEX Malicious
Rising Trojan.Kryptik!1.AD41 (CLASSIC)
Yandex Trojan.GenAsa!W2lzyLyzry4
TACHYON Trojan/W32.Agent.551424.CG
eGambit Unsafe.AI_Score_99%
Fortinet W32/Kryptik.HGZD!tr
MaxSecure Trojan.Malware.7164915.susgen
AVG Win32:Filecoder-BG [Trj]
Cybereason malicious.22cb80
Avast Win32:Filecoder-BG [Trj]
Qihoo-360 HEUR/QVM20.1.3A86.Malware.Gen

How to remove Ransom:Win32/Cerber.K?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Trojan.Generic.35791346”?

The Trojan.Generic.35791346 is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

Malware.AI.1480269634 removal tips

The Malware.AI.1480269634 is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

Adware.BrowseFox.305 removal

The Adware.BrowseFox.305 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32/AutoRun.VB.AUW (file analysis)

The Win32/AutoRun.VB.AUW is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Trojan:Win64/Metasploit!pz removal guide

The Trojan:Win64/Metasploit!pz is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

What is “Win32/Agent_AGen.BLW”?

The Win32/Agent_AGen.BLW is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago