Ransom Trojan

What is “Trojan.Ransom.Cerber.EO”?

Malware Removal

The Trojan.Ransom.Cerber.EO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.EO virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • PlugX
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Ransom.Cerber.EO?


File Info:

crc32: DCF3AC3A
md5: ab4bc6ef622cb1864fc6a97270071acd
name: AB4BC6EF622CB1864FC6A97270071ACD.mlw
sha1: 532841bec4518ddae0e047e1e50e55609d0c4fbd
sha256: c3910e6b443138920109fc82911418e739f16d4e2f577fbadc2a6016f4f5229a
sha512: 750a7009904bc96c5313ccb3f739f935aca051a6224f1708befa80b8bef3925e58588c211a811791cd91138d28dc3909c14e7fd18169619829ce188c5cd9593a
ssdeep: 6144:PB+pgUuNYHXJHKJfvJP6MrQLFKYcd1/P0fLPY:PgGNkAJsMwcP8fjY
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: John T. Haller
InternalName: FileZilla Portable
FileVersion: 1.6.10.0
CompanyName: PortableApps.com
LegalTrademarks: PortableApps.com is a Trademark of Rare Ideas, LLC.
Comments: Allows FileZilla to be run from a removable drive. For additional details, visit PortableApps.com/FileZillaPortable
ProductName: FileZilla Portable
ProductVersion: 1.6.10.0
FileDescription: FileZilla Portable
OriginalFilename: FileZillaPortable.exe
Translation: 0x0409 0x04b0

Trojan.Ransom.Cerber.EO also known as:

K7AntiVirusTrojan ( 005011fe1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.B
ALYacTrojan.Ransom.Cerber.EO
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.710
SangforRansom.Win32.Zerber.erwj
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Zerber.18e997e3
K7GWTrojan ( 005011fe1 )
Cybereasonmalicious.f622cb
CyrenW32/Cerber.WVKH-8059
SymantecPacked.NSISPacker!g4
ESET-NOD32Win32/Filecoder.Cerber.E
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.erwj
BitDefenderTrojan.Ransom.Cerber.EO
NANO-AntivirusTrojan.Nsis.Zerber.ekfoqv
MicroWorld-eScanTrojan.Ransom.Cerber.EO
TencentWin32.Trojan.Zerber.Lneh
Ad-AwareTrojan.Ransom.Cerber.EO
SophosMal/Generic-R + Mal/Cerber-AA
ComodoMalware@#nvo1wmqrqlrk
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.F117A2
McAfee-GW-EditionBehavesLike.Win32.ICLoader.dc
FireEyeGeneric.mg.ab4bc6ef622cb186
EmsisoftTrojan.Ransom.Cerber.EO (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1117985
KingsoftWin32.Troj.Ransom.EO.(kcloud)
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Ransom.Cerber.EO
GDataTrojan.Ransom.Cerber.EO
TACHYONRansom/W32.Cerber.229645
AhnLab-V3Trojan/Win32.Cerber.C1730368
McAfeeArtemis!AB4BC6EF622C
MAXmalware (ai score=100)
MalwarebytesRansom.Cerber
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.F117A2
FortinetW32/Injector.PG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HyoDEpsA

How to remove Trojan.Ransom.Cerber.EO?

Trojan.Ransom.Cerber.EO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment