Ransom Trojan

How to remove “Trojan.Ransom.Cerber.AT”?

Malware Removal

The Trojan.Ransom.Cerber.AT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.AT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Cerber ransomware
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Ransom.Cerber.AT?


File Info:

crc32: 684887A2
md5: b35cfab664ce780a199433e606f928a4
name: B35CFAB664CE780A199433E606F928A4.mlw
sha1: 3727d9dc9de1f2e74d2587e2da7b538b6c012650
sha256: 27b3892cdc753d76dbd61f56108c7bea4b8548fb522935182a8d45f1e97c9cb9
sha512: 839a8a725f0a6bb543fef0280617288e26d88fb7d6fd332b316e955e38e921a9823af34a3d6e29cadcfc33e22bd474a2d8c2fa7d410b798e37cbbbe59b40ddd3
ssdeep: 6144:lwNY0ChuzaxVL94gsOkOn6tjFhgaoKVBTb+Btl7fbR5wI5Mg8QC1N1Idc:lwkhzVL98FO6XhgxKVc7DjwcMgilj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright(c) 2007 Corel Corporation
InternalName: CdrConv
FileVersion: 14.0.0.701
CompanyName: Corel Corporation
Built on: Fri 11/21/2008 21:36:24.30
LegalTrademarks: Corel, CorelDRAW, Corel DESIGNER, Corel R.A.V.E., Corel PHOTO-PAINT, CorelTRACE and Corel CAPTURE are trademarks or registered trademarks of Corel Corporation and/or its subsidiaries in Canada, the U.S. and/or other countries.
ProductName: Corel Graphics Applications
Language Build ID: 0
ProductVersion: 14.0.0.701
FileDescription: CdrConverter
OriginalFilename: CdrConv.exe
Translation: 0x0409 0x04e4

Trojan.Ransom.Cerber.AT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.G4
ALYacTrojan.Ransom.Cerber.AT
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.3334
SangforRansom.Win32.Cerber_47.se
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005224381 )
Cybereasonmalicious.664ce7
BaiduWin32.Trojan.Kryptik.avk
CyrenW32/Cerber.F.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32Win32/Filecoder.Cerber.B
APEXMalicious
AvastWin32:Filecoder-BG [Trj]
ClamAVWin.Ransomware.Cerber-9805143-0
KasperskyUDS:Packed.Win32.Mentiger.gen
BitDefenderTrojan.Ransom.Cerber.AT
NANO-AntivirusTrojan.Win32.Mentiger.evghpd
MicroWorld-eScanTrojan.Ransom.Cerber.AT
TencentMalware.Win32.Gencirc.10b1a057
Ad-AwareTrojan.Ransom.Cerber.AT
SophosML/PE-A + Mal/Cerber-K
ComodoTrojWare.Win32.Ransom.Cerber.HX@6lfg5l
BitDefenderThetaGen:NN.ZexaF.34686.wq1@aKvy4Ihi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMEJ4
McAfee-GW-EditionBehavesLike.Win32.Swizzor.fh
FireEyeGeneric.mg.b35cfab664ce780a
EmsisoftTrojan.Ransom.Cerber.AT (B)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Mentiger.dhg
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Cerber.A
GDataTrojan.Ransom.Cerber.AT
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-CBER!B35CFAB664CE
MAXmalware (ai score=99)
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.AI.2536435905
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMEJ4
RisingRansom.Cerber!8.3058 (CLOUD)
YandexPUA.Downloader!7ciU4jLRZbo
IkarusTrojan.Win32.Filecoder
FortinetW32/Kryptik.HCAW!tr
AVGWin32:Filecoder-BG [Trj]
Paloaltogeneric.ml

How to remove Trojan.Ransom.Cerber.AT?

Trojan.Ransom.Cerber.AT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment