Ransom Trojan

Trojan.Ransom.Cerber.P removal

Malware Removal

The Trojan.Ransom.Cerber.P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.P virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan.Ransom.Cerber.P?


File Info:

crc32: BE7D26A2
md5: 58dd66e7bf07aa918d446cf7fa6f008a
name: 58DD66E7BF07AA918D446CF7FA6F008A.mlw
sha1: 0ef5c290d33f630cd72fecb86368da0177ebd730
sha256: c2e0f68d738978ac026540d423b925e0409bb2e2484b2b4878d6709c8e3f6536
sha512: c8079396240cf0198a29d15fa9423d5873e891034cb3c98b766556e61f6e96c5b6da25cb1382f6b85cfa81f4188cbca40604f5cad4e8f08f962ff297f50aeac7
ssdeep: 3072:LeNTh10HJEWsHtRPpdidtRssM5biUUkTdc1W+piKH2LS13/Nx9Ug8H:qNzsanNRhERobiU8nsS137y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Metanotal6
FileVersion: 1.00
CompanyName: @
ProductName: Abdicating2
ProductVersion: 1.00
OriginalFilename: Metanotal6.exe

Trojan.Ransom.Cerber.P also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004e189a1 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.38035
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A3
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
ZillyaTrojan.Cerber.Win32.19
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.715f317a
K7GWTrojan ( 004e189a1 )
Cybereasonmalicious.7bf07a
CyrenW32/Cerber.JBBX-0624
SymantecRansom.Cerber
ESET-NOD32Win32/Filecoder.Cerber.B
ZonerTrojan.Win32.41199
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-7432269-0
KasperskyTrojan-Ransom.Win32.Zerber.aph
BitDefenderTrojan.Ransom.Cerber.P
NANO-AntivirusTrojan.Win32.Packed2.efgzns
ViRobotTrojan.Win32.U.Cerber.184576
MicroWorld-eScanTrojan.Ransom.Cerber.P
TencentMalware.Win32.Gencirc.10b9b5f3
Ad-AwareTrojan.Ransom.Cerber.P
SophosMal/Generic-R + Troj/Ransom-DDM
ComodoMalware@#xq2lbtjm6fpr
BitDefenderThetaGen:NN.ZevbaF.34628.lm1@aS0Is8li
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.JKC
McAfee-GW-EditionGeneric.ys
FireEyeGeneric.mg.58dd66e7bf07aa91
EmsisoftTrojan.Ransom.Cerber.P (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.ec
WebrootW32.Trojan.Gen
AviraTR/FileCoder.Locky.65778
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Ransom.Cerber.P
GDataWin32.Trojan.Agent.4V2FNX
TACHYONRansom/W32.VB-Cerber.184576
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeeGeneric.ys
MAXmalware (ai score=100)
VBA32Hoax.Zerber
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/WLT.B
TrendMicro-HouseCallRansom_CERBER.JKC
RisingRansom.Cerber!8.3058 (CLOUD)
YandexTrojan.Zerber!XJVc3zJwdo0
IkarusTrojan.Win32.Filecoder
FortinetW32/Injector.CZOJ!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Ransom.Cerber.HwMA8FwA

How to remove Trojan.Ransom.Cerber.P?

Trojan.Ransom.Cerber.P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment