Ransom Trojan

How to remove “Trojan.Ransom.Cerber.CT”?

Malware Removal

The Trojan.Ransom.Cerber.CT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.CT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings

How to determine Trojan.Ransom.Cerber.CT?


File Info:

crc32: E85658BA
md5: ae31055e4d74910381e0411f153fba6f
name: AE31055E4D74910381E0411F153FBA6F.mlw
sha1: 12e3175fd99524098b897be749992326c9e2cfc3
sha256: 414416eab0551d06c7ba9e9378a1117ecfa308e2a0aa298c4035e327e9db5f1e
sha512: 683bda41de4d1634c5ad2b6c86e2956ec5ef4de9b3368361427dc0ae3ad4499c1c2ae6902c1a869f15d697979793ce1ff6bd1556633882e9e53fa1a9bd4a72db
ssdeep: 3072:YuQuajpvic8TG1uuEDe9CWz6g0o2Me446FIUkfJ/0uD:Yualic8TfuM20o2Me47YD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompanyName: DT Soft Ltd
Translation: 0x4009 0x04b0

Trojan.Ransom.Cerber.CT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Papras.2851
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.CT
CylanceUnsafe
ZillyaTrojan.Generic.Win32.74294
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Kryptik.0731ac36
K7GWTrojan ( 005224381 )
Cybereasonmalicious.e4d749
BaiduWin32.Trojan.Kryptik.bak
CyrenW32/Cerber.F.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FKVG
APEXMalicious
AvastWin32:Filecoder-BG [Trj]
ClamAVWin.Ransomware.Razy-9827716-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.CT
NANO-AntivirusTrojan.Win32.Papras.evdjxg
MicroWorld-eScanTrojan.Ransom.Cerber.CT
TencentWin32.Trojan.Generic.Lnxp
Ad-AwareTrojan.Ransom.Cerber.CT
SophosML/PE-A + Mal/Cerber-K
ComodoTrojWare.Win32.Boaxxe.SA@70kkpx
BitDefenderThetaGen:NN.ZexaF.34790.wq0@aOGHdiki
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM620
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ft
FireEyeGeneric.mg.ae31055e4d749103
EmsisoftTrojan.Ransom.Cerber.CT (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bqvlj
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_53%
Antiy-AVLTrojan/Generic.ASMalwS.1CAA30B
MicrosoftTrojanSpy:Win32/Ursnif!rfn
ArcabitTrojan.Ransom.Cerber.CT
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan.Win32.Menti.gen
GDataTrojan.Ransom.Cerber.CT
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-GCQ!AE31055E4D74
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Papras
MalwarebytesEmotet.Trojan.Stealer.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCERBER.SM620
RisingTrojan.Kryptik!1.AE9C (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HGZD!tr
AVGWin32:Filecoder-BG [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBEpsA

How to remove Trojan.Ransom.Cerber.CT?

Trojan.Ransom.Cerber.CT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment