Malware

About “ML/PE-A + Troj/Cerber-AHR” infection

Malware Removal

The ML/PE-A + Troj/Cerber-AHR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Cerber-AHR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine ML/PE-A + Troj/Cerber-AHR?


File Info:

crc32: 9016C3A0
md5: 143cde8decfd78112432840904a1fb58
name: 143CDE8DECFD78112432840904A1FB58.mlw
sha1: aa33530b8f2c0c4ffd6aacbf59e96d24402e1aa6
sha256: 7f30105a05afb086f9cbe369f5276f7206279a741c2f0209216c6dfe27b8ff14
sha512: 59eda1064333acaba8050d581191e1a70ff95afbeb3805b517ab1e3e5e5af473c23a03e253f966140f50d0f9acbb676d3b5f7376f808b22a50b7fe5cafe76013
ssdeep: 6144:2JYEh79RAc1U2e2M2cYkaQ2FbGZiaqaWi9u6V7jujtjRZJnBPZI/jJjUjTjlg7UC:MYGHi2e2MFYaBZi7aWi9u6ehxiEmqux
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Troj/Cerber-AHR also known as:

K7AntiVirusTrojan ( 005047df1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.18891
ClamAVWin.Ransomware.Cerber-9817130-0
CAT-QuickHealRansom.Zerber.S767462
ALYacGen:Variant.Ransom.Sage.110
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Ransom.Sage.110
K7GWTrojan ( 005047df1 )
Cybereasonmalicious.decfd7
CyrenW32/Cerber.ZNXO-4392
SymantecTrojan.Gen.2
ESET-NOD32Win32/Filecoder.Cerber.G
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Filecoder.enehlq
MicroWorld-eScanGen:Variant.Ransom.Sage.110
TencentMalware.Win32.Gencirc.10bba918
Ad-AwareGen:Variant.Ransom.Sage.110
SophosML/PE-A + Troj/Cerber-AHR
ComodoMalware@#3bc49ob2jo5zg
BitDefenderThetaGen:NN.ZexaF.34170.DuX@a0W@Dzbi
TrendMicroRansom_CERBER.F117D3
FireEyeGeneric.mg.143cde8decfd7811
EmsisoftGen:Variant.Ransom.Sage.110 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.bgz
AviraHEUR/AGEN.1127187
Antiy-AVLTrojan/Generic.ASMalwS.1F3A494
GDataGen:Variant.Ransom.Sage.110
AhnLab-V3Malware/Win32.Ransom_.C1904020
Acronissuspicious
VBA32Hoax.Zerber
MAXmalware (ai score=89)
TrendMicro-HouseCallRansom_CERBER.F117D3
RisingTrojan.Generic@ML.100 (RDML:OZBwL40Cam4LrjDlIvaQqg)
YandexTrojan.Filecoder!EH1JIpmXNuc
IkarusTrojan-Ransom.GandCrab
FortinetW32/Filecoder_Cerber.G!tr
PandaTrj/CI.A

How to remove ML/PE-A + Troj/Cerber-AHR?

ML/PE-A + Troj/Cerber-AHR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment