Cerber 4.0 Ransomware Files

File Name Size Detection Count MD5
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{55B72E38-19F0-0122-695E-47D7AADFDEDC}\logman.exe 233,605 7,147 3f6b7343a396aaabda7cefcf13082d26
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{BC938CB2-9C1B-4D74-24DE-2E5EC4C86636}\dcomcnfg.exe 727,846 4,200 dc68c7b1c3042dd4d40ee946dee1981a
%APPDATA%\# DECRYPT MY FILES #.vbs 246 2,457 d3e80e1e6dffc81a2e72c05c9b482fc6
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{97511944-496B-5CC4-B91B-94A328CB9203}\ktmutil.exe 542,999 2,294 434a0b804ed5a1dff944372ab0eaa4cc
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{D356F669-87E8-7418-7B35-4816AA44C40C}\LocationNotifications.exe 782,080 1,869 031a213144c5ff102217ddc00adf66d0
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Startup\README.hta 4,108 1,786 23351151a066a43ffd0e98979f6939cc
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{2B00BCC3-42B1-1D8E-FBA1-383F3D0BDE8C}\help.exe 439,427 1,598 22b3148a9cbfa38086e8f683c95964f9
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{DDC5E9C6-2A32-2A2B-FC96-675564C8B2D5}\certreq.exe 272,592 1,501 9971ec7ec1d58b95dd24394c7594dc12
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{A74EDD94-8792-864E-CD46-B870E92971B2}\iscsicli.exe 396,544 1,400 640755628b77e5128e10bf15893865ff
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{96C3F6CD-BBF7-36F9-2D69-39E5A9BCE5E1}\wecutil.exe 249,088 1,400 eb11a0c7f6767ef3617bef29a0125936
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{6653DDDB-DC3B-BBE0-0E02-930E09CB2E8A}\certreq.exe 352,521 1,210 0d0d0fa005247fb0b4720336bfa46c69
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{FFB723EA-791B-AD23-6577-44F26E288641}\wuapp.exe 178,494 1,189 f0f52996245a3d10f34ea7875974f98b
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{1AA55626-AC56-4563-CBB6-A483C4E722F7}\Utilman.exe 204,434 1,089 056f18639bf6adea8c35cfc5e32cd0e3
%APPDATA%\# DECRYPT MY FILES #.vbs 219 1,005 35a3e3b45dcfc1e6c4fd4a160873a0d1
%APPDATA%\{11639717-8C09-D566-9EF6-AD45260A8C71}\ReAgentc.exe 195,204 802 4655d3e3498f075562f14ba38b2f5e60
%APPDATA%\# DECRYPT MY FILES #.vbs 216 700 48ac29422570636cae371b68c858b988
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{58EE0051-A6B2-735D-4446-78F559F1944F}\iscsicli.exe 276,210 699 fbe207f6b013afae50ec2d6612d5e682
%APPDATA%\# DECRYPT MY FILES #.vbs 225 676 f6d629f2a4c0815f005230185bd892fe
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{7BC81A7F-9099-C59A-4658-143881482D38}\sdbinst.exe 278,784 640 4d03461e9eee09db0100910dc68736b9
%USERPROFILE%\Start Menu\Programs\Startup\README.hta 63,111 629 8c59af32be34fa66668dec4e4a5a0fe6
%APPDATA%\{420B74B0-6759-19C6-0C6F-3E14D0BDC32A}\synctask.exe 311,296 621 49ad394e46a0dae85097b297bbed2800
%APPDATA%\{2F3AA0F6-976C-4b02-A66A-5D1DEA00811F}\InstallHelp.exe 945,152 584 4ed76fc058b1017fcb0da50f0750e487
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{62E00AE3-5835-75AF-A74E-DAB5F6089633}\shrpubw.exe 188,039 578 356ea1ee79f9c1f7a4b713028c7f20b5
%APPDATA%\# DECRYPT MY FILES #.vbs 234 537 6f84dbf74ef41dc3d861f5fb3e0f45ff
%APPDATA%\# DECRYPT MY FILES #.vbs 208 523 0f432f89aeb7c3a417613778382eff30
D:\B?NG GI? B? ??I T?N VI?T\# DECRYPT MY FILES #.vbs 204 496 f4f62c6f03227c16f4224d94f3df3290
%APPDATA%\# DECRYPT MY FILES #.vbs 252 462 18d46f5d8ebd3c7d6df0c7a8fd1bd64d
%ALLUSERSPROFILE%\# DECRYPT MY FILES #.vbs 213 447 1c2a24505278e661eca32666d4311ce5
%APPDATA%\{46B13E62-A171-6C43-F86C-67BAEC00A0BD}\Updater.exe 380,416 417 50d0c22eeda481127c0a87d1440bd040
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{42C98EC4-EC5F-FE36-2A6F-0B0F385BBD36}\dccw.exe 635,649 412 91f0bbfa3e515144e08df88c9a65e71a
%USERPROFILE%\Start Menu\Programs\Startup\README.hta 63,111 402 c12d0e75730483ad5622c06bf0f2dfac
%APPDATA%\# DECRYPT MY FILES #.vbs 231 397 9d8c4bfbd009c4d6001e2125abaa8b02
%APPDATA%\{B14B87F0-9419-EA86-FF2F-CD5423FD306A}\SynHelper.exe 304,640 395 519a98004850bb8d671b37ad5a679531
%APPDATA%\{51FBCA03-C471-95E3-EEA4-70CE8949A24D}\pricefountainupdateverupdate.exe 274,944 385 b72c37b239dd2f4dad1f386b3a4b911e
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{BB5C4DEE-2593-98EF-33D8-00FDD11BA0DD}\rasdial.exe 195,848 378 e0e6b41200a0079a1285852c3153998c
%APPDATA%\{645C2F8F-F5A5-7886-7E1D-55334ADDC715}\sync.exe 415,232 373 02993f6cbe9d92e4984d587fc26525a8
%USERPROFILE%\README.hta 4,108 360 c409056659364d79edcf6e0da88e5bcb
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{B6724642-9745-6D9C-726C-2FA74D8F74AC}\bootcfg.exe 195,894 356 cdfe68a00c7c7766bc88b25b38d85a65
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{B9B945ED-24CB-0419-99B9-7B5BA171E83F}\WPDShextAutoplay.exe 396,032 350 20feb4e0a8e32043b17e21e9744a13d6
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{8417F8C6-5E6B-0A39-FCCA-108BED1E5FF2}\icsunattend.exe 250,138 348 65267f95c982712fc1abd86d28241bb7
%APPDATA%\{5ACA0CD5-1E89-4CC2-DA53-0D7C4BFC3CFF}\synctask.exe 342,016 348 db6e02fb1434fcd13e52762381d3ac2f
%APPDATA%\{5F6354E3-BFB4-2443-C0DE-164E962AF494}\syncversion.exe 427,008 347 9f100c0775bcc77d0e785d6a11acf4be
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{D8118AF0-6027-A2A0-A9D7-3C81E75B5593}\at.exe 199,430 342 bd25b0b07c6a09191cdc6fedea022949
%APPDATA%\{6A98394A-0B2B-0A56-25B4-AF47E9810A94}\icardagt.exe 397,568 340 39462c44f21cfaae2d5b1754218f784a
%APPDATA%\{5F7A8D01-0C53-8D9C-514D-77B40E2F3EA9}\UpdateTask.exe 396,800 338 ef7c094275615af779d155a1e481683d
%APPDATA%\{3F67DBB1-6FBD-096D-2009-28B029DFE00F}\Sync.exe 331,776 337 3b520e88b45d8669ece56c38e3dfdf0f
%APPDATA%\{E9BF2668-AADF-0F97-8C37-10308AF766B2}\gpresult.exe 243,505 331 853f1b50506814aa6bd7af9931a5d0be
%SystemDrive%\Documents and Settings\Tomas\Application Data\_README_.hta 67,727 302 0a7fb1f205301a40ad463491a91d77ad
%APPDATA%\{1796B844-2E3A-6B7F-AE85-38E31CC26AB7}\sync.exe 420,864 281 8e3f31166b9e6663e6b7247e47ce8716
%APPDATA%\{6DEDED7B-47FB-72F4-A3E4-7B40A141B2FA}\Sync.exe 382,976 275 ce590a8316784f0bcded1991ebf68b93
%APPDATA%\{06DF0841-E150-11DB-E29C-3A680C37D020}\syncversion.exe 396,288 271 30c42c50fc4728245bf67e46b2b29a9a
%APPDATA%\{32CCAE5D-CDA6-5C46-E7F6-2EAD56933545}\ProductUpdate.exe 350,720 270 0b7e0c72fa4643676879c9dc7ca8ec73
%APPDATA%\{52155399-0CAC-C1D6-31F0-7B8667476241}\SyncTask.exe 408,576 264 ab632e4d74f52279a7c1f880439f612b
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{46BFA423-CE4C-0629-A21B-15EAF3A6A143}\dialer.exe 246,039 264 59974f223fcf42327e9e260e00bb01e5
%APPDATA%\{3FDB0D64-8AAE-CEB1-BB23-2200EFE2799A}\productupdate.exe 494,080 259 9de51383978ecdfa943fc44c1dea89d2
%APPDATA%\{4BCF77F0-80E3-4C98-E6BE-33D7B8E78393}\syncversion.exe 371,200 256 ae68f524aa1db4871bda6613616d43c8
%APPDATA%\{081C35F3-6243-81A1-3A45-093C032C2E9A}\mountvol.exe 212,269 254 064de7c80f1e37a70ca7b6b72113f3a3
%SystemDrive%\Users\worker\README.hta 4,086 253 c1910896218ab6aac5f4141e6671183d
%APPDATA%\{6C4F68E0-BD51-69DA-6644-47E5099E8ACD}\SyncTask.exe 323,584 252 f794385b9da4c48cb0cbf1e689139119
%APPDATA%\{2A8B8412-FAD5-9F8B-4C79-2DEE0EB04582}\UpdateTask.exe 484,352 248 2b2e6a8a09b2b89c06527147fb2fdb14
%APPDATA%\{244812F3-011A-7F85-6A2C-5857B6FEA569}\UpdateTask.exe 374,784 245 9a3eb1d0fc40ca2e8df53fea60150acb
%APPDATA%\{97CFA174-B29D-CC02-D9AB-EBD0057916EE}\syncversion.exe 318,464 239 43c51f23fabd2aca5991e65c62dd6081
%APPDATA%\{6830E82A-B404-1411-131E-2422ED48D29F}\SyncTask.exe 357,888 238 cdaca3a6f98c6c846db3b3bf62a82aa4
%APPDATA%\{DC62EAD9-F930-87AF-9206-A07D4ED45D43}\syncversion.exe 306,688 233 ab5d2c4b8bfd7cf7dede75b2046629f4
%ALLUSERSPROFILE%\_README_NVSKN3_.hta 67,748 231 6ac7f4dbc0dcb2f206f40ffad53adfbb
%APPDATA%\{45C5DA69-0997-6491-9C3A-01D889177155}\ProductUpdate.exe 334,848 230 0291cebd0f539b231ed78ecb9c2773f1
%APPDATA%\{0527720E-EA10-60D1-C5AB-32F5E9B479E4}\productupdate.exe 393,216 227 95c3ae55862a9c8ca7cbbc0bcbc19c5f
%APPDATA%\{5476C7F9-F285-5562-136B-37626EE0A237}\Updater.exe 313,856 223 f93a1ae6af042e37056ce5f83dd202d0
%APPDATA%\{0DB40094-7AE8-5E8B-8D9B-4070BED95EE0}\updatetask.exe 294,400 222 2c9c06cf5a8e8d945d881bb1b8bae04b
%APPDATA%\_README_.hta 67,727 218 8481443bdb44aa960c30b8021a2e395a
%APPDATA%\{F473D0CD-0F9B-3447-D705-E535A5BBC2EA}\ntkrnlpa.exe 259,328 216 f40bc4088b5cbf4829f401449001eead
%APPDATA%\{11A4DFB3-F261-A42B-3AB9-2AEA92C1E0A0}\ProductUpdate.exe 477,184 215 1cb437e1723e7284073b5d039fe78cd4
%APPDATA%\{141F2D91-E14C-A52B-7625-77A42486B28C}\Sync.exe 333,824 214 d3e710e4f5dcf84931a41645c5415e9e
%APPDATA%\{333E238A-FDC3-B8F4-6C52-1B0EE2A822E2}\updater.exe 405,504 213 440d118897c50d403bfcf671d370207c
%ALLUSERSPROFILE%\README.hta 63,083 207 b35bdb801c3d2a0eb78675c30f00b735
%APPDATA%\{7A978B89-7279-D485-45F3-4FD4E16FC5D4}\ProductUpdate.exe 366,592 207 bcd3f5775c661a4e95134cf8ff2c230d
%APPDATA%\{33BAF060-DB38-0DCE-BDEB-0201EFE679E0}\Updater.exe 333,824 205 12855d346c78efa6595ce67ca485fad9
%WINDIR%\system32\config\systemprofile\AppData\Roaming\{69642301-0A55-0AFC-CCAE-FFD9082C3EBA}\grpconv.exe 163,328 205 334ae3690413230fc0ba95434fe6ee54
%APPDATA%\{A2A1941A-87F3-F96C-ECC5-DEBE30172380}\Updater.exe 339,968 197 426f1f2c489b48b1824ad7b69649dd09
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Startup\README.hta 4,453 196 41df3867bbbf5c99b55d8ec72a931ae9
%APPDATA%\{0D87F79C-0071-BF74-F16C-14AD5962511A}\updatetask.exe 276,992 193 be77a7d296f1a1201338a1d632cf9e3c
%APPDATA%\{9558A3E3-B00A-CE95-DB3C-E94707EE1479}\SynHelper.exe 307,712 193 39b098b3d49bdf66f707c497bc543edf
%APPDATA%\{007236C9-2520-5BBF-4E16-7C6D92C48153}\SynHelper.exe 455,168 192 f9551f6b9b01cbc1297de99758d43030
%APPDATA%\{718A4731-54D8-2A47-3FEE-0D95E33CF0AB}\helperupdate.exe 461,312 191 a138e1810d9bc425957c852dbcbcc5ec
%APPDATA%\{0213BB18-AF46-A414-2E97-31374456A011}\productupdate.exe 525,312 186 4cfdfa7d1db9af519087e76297d18d9f
%APPDATA%\README.hta 63,111 185 5edf5d47f5d40ed06730cf4fb45e3a29
%APPDATA%\{5D3C548E-147E-A913-D7DB-217BCD6CA17D}\SyncVersion.exe 536,576 183 7f3f9b904fa78dd34976daeb0dd6535d
%APPDATA%\README.hta 63,111 182 60b0d6c8cfde0bff0a1a9d6ca6b5e93c
%APPDATA%\README.hta 63,111 178 c66e4af0fe95bc3f5ff8694d4ddd3d33
%APPDATA%\README.hta 63,111 173 039e9c93bd465d729a4ed741b9c2a9ce
%USERPROFILE%\Start Menu\Programs\Startup\README.hta 63,111 167 7e277ee5d87e2b6fcf8b66988880ac6c
%ALLUSERSPROFILE%\Readme.hta 9,072 167 e125ef487472bfdd17d7e3e7e237d0d9
%WINDIR%\SysWOW64\config\systemprofile\AppData\Roaming\{85033057-ED46-A916-DA39-C5FDD78D7C6C}\SndVol.exe 251,508 153 f14425ed138ce9a776d14e657e50bc26
%SystemDrive%\Users\UpdatusUser\AppData\Roaming\README.hta 63,059 153 356f1d64c43d7270702390dc000cc822
%APPDATA%\README.hta 63,059 149 56cbb0d10795bb21736c74ae1d3aaea4

Home > Threat Database > Cerber 4.0 Ransomware > Cerber 4.0 Ransomware Files
Need Help? Call SpyHunter Customer Service!
Worldwide: +353 1 907 9880
USA (Toll Free): +1 (888) 360-0646