Ransom Trojan

GenPack:Trojan.Ransom.Cerber.QF removal guide

Malware Removal

The GenPack:Trojan.Ransom.Cerber.QF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Trojan.Ransom.Cerber.QF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine GenPack:Trojan.Ransom.Cerber.QF?


File Info:

crc32: 55D0D059
md5: b64db45e9285f1acb110a5006b84524a
name: B64DB45E9285F1ACB110A5006B84524A.mlw
sha1: 51676c367f7006b6fc79219c949a203b1945d22d
sha256: 8ec501fc108f6238d69d4a1ffed8bae36c7c325bc1eff07eb92fdec7c05af620
sha512: 77d675cdef6d35e799a68fd97e93c7a3c0c224570dffb9d978d1fbf57458fb31252d7dcf3fda0d9b0c451a696b6a294dad660f16ffb73aa38abf3bb543d24d3d
ssdeep: 6144:6JhZnjvSrWLJklEQf0Eb6TrCPY7LlhW0GbwMPJ95slgcadg8JwR3Zv78VXsVz:6JhZxLKDc+4hhW0Kwm1sic5zZv78hs
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: Copyright(c) 2007 Corel Corporation
InternalName: CdrConv
FileVersion: 14.0.0.701
CompanyName: Corel Corporation
Built on: Fri 11/21/2008 21:36:24.30
LegalTrademarks: Corel, CorelDRAW, Corel DESIGNER, Corel R.A.V.E., Corel PHOTO-PAINT, CorelTRACE and Corel CAPTURE are trademarks or registered trademarks of Corel Corporation and/or its subsidiaries in Canada, the U.S. and/or other countries.
ProductName: Corel Graphics Applications
Language Build ID: 0
ProductVersion: 14.0.0.701
FileDescription: CdrConverter
OriginalFilename: CdrConv.exe
Translation: 0x0409 0x04e4

GenPack:Trojan.Ransom.Cerber.QF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0050b53a1 )
DrWebTrojan.Encoder.10752
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A3
ALYacGenPack:Trojan.Ransom.Cerber.QF
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.3886
SangforRansom.Win32.Cerber.J
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaRansom:Win32/Cerber.dd3968eb
K7GWTrojan ( 0050b53a1 )
Cybereasonmalicious.e9285f
CyrenW32/Trojan.HMYD-1349
SymantecRansom.Crypto!im
ESET-NOD32Win32/Filecoder.Cerber.K
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.erid
BitDefenderGenPack:Trojan.Ransom.Cerber.QF
NANO-AntivirusTrojan.Win32.Zerber.etmwcj
MicroWorld-eScanGenPack:Trojan.Ransom.Cerber.QF
TencentWin32.Trojan.Raas.Auto
Ad-AwareGenPack:Trojan.Ransom.Cerber.QF
SophosML/PE-A + Mal/Cerber-K
ComodoTrojWare.Win32.Skeeyah.AG@75jdtz
BitDefenderThetaGen:NN.ZexaF.34608.umuaaGFjcBhi
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCERBER.SMONT6
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.b64db45e9285f1ac
EmsisoftGenPack:Trojan.Ransom.Cerber.QF (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1119266
eGambitUnsafe.AI_Score_91%
MicrosoftRansom:Win32/Cerber.J
ArcabitGenPack:Trojan.Ransom.Cerber.QF
GDataGenPack:Trojan.Ransom.Cerber.QF
AhnLab-V3Trojan/Win32.Zerber.C1984964
Acronissuspicious
McAfeeGeneric.ckg
MAXmalware (ai score=100)
VBA32Hoax.Zerber
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPCERBER.SMONT6
RisingRansom.Cerber!8.3058 (C64:YzY0On/1ABxr+HPl)
IkarusTrojan.Win32.Filecoder
FortinetW32/Kryptik.FQOG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HgIASOgA

How to remove GenPack:Trojan.Ransom.Cerber.QF?

GenPack:Trojan.Ransom.Cerber.QF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment