Ransom Trojan

Trojan.Ransom.Cerber.1 removal guide

Malware Removal

The Trojan.Ransom.Cerber.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.1 virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ransom.Cerber.1?


File Info:

crc32: 84DC2C90
md5: b7ae0ca60823e985cf9c6ab7ddeebb06
name: B7AE0CA60823E985CF9C6AB7DDEEBB06.mlw
sha1: 9fb1c2bcb86d1bf2d23d3400ae34b57031dbb713
sha256: 7a61ca0cd624f85a02a3d168764a589593ff19ca4edb41be92f16ffb521ffad1
sha512: bb8e44d1d525693c1f7aed9537a91bdf3e446ee3c8034dbf2d12e4538362eae48a2ab233d01a8923b8dcd35988d5c7ec1bb03b488c6ffc6ee4591e8394eb2349
ssdeep: 3072:6LhF64nITEkExh5mry7qgIJsvArxl0BrlnURZYvoVgNXhlvQ/+Us2HKIacaUc22J:5Mcso+rlURZqoVgXhs/DdDYuWX5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Comments: Tool used internally by Total Commander, do not start directly!
CompanyName: Ghisler Softwa re GmbH

Trojan.Ransom.Cerber.1 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.b7ae0ca60823e985
McAfeeGenericRXAA-AA!B7AE0CA60823
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 004fa86d1 )
K7AntiVirusTrojan ( 004fa86d1 )
TrendMicroRansom_HPCERBER.SMALY5A
BaiduWin32.Trojan.Kryptik.anp
CyrenW32/Cerber.VJAM-1855
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Ransomware.Cerber-9777248-0
KasperskyTrojan-Ransom.Win32.Zerber.jcb
RisingTrojan.Win32.Cerber.a (CLASSIC)
Ad-AwareTrojan.Ransom.Cerber.1
EmsisoftTrojan.Ransom.Cerber.1 (B)
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
DrWebTrojan.Encoder.5189
InvinceaML/PE-A + Mal/Cerber-B
McAfee-GW-EditionBehavesLike.Win32.BadFile.dh
SophosMal/Cerber-B
GDataTrojan.Ransom.Cerber.1
JiangminTrojan.Zerber.eli
MaxSecureTrojan.Malware.300983.susgen
MAXmalware (ai score=82)
GridinsoftRansom.Win32.Ransom.oa!s2
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmTrojan-Ransom.Win32.Zerber.jcb
MicrosoftRansom:Win32/Cerber.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.C1511907
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.qq1@aOqv04qi
ALYacTrojan.Ransom.Cerber.1
TACHYONRansom/W32.Cerber.276629
VBA32BScope.Trojan.Vucha
MalwarebytesRansom.Cerber
ZonerTrojan.Win32.44666
ESET-NOD32a variant of Win32/Kryptik.FDHE
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
YandexTrojan.GenAsa!ZlIOe44JNcM
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HCAW!tr
WebrootW32.Trojan.Gen
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.60823e
Qihoo-360HEUR/QVM20.1.38DF.Malware.Gen

How to remove Trojan.Ransom.Cerber.1?

Trojan.Ransom.Cerber.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment