Ransom Trojan

How to remove “Trojan.Ransom.Cerber.QX”?

Malware Removal

The Trojan.Ransom.Cerber.QX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.QX virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.blockcypher.com
hjhqmbxyinislkkt.1j9r76.top

How to determine Trojan.Ransom.Cerber.QX?


File Info:

crc32: 5EBEC062
md5: 830780e5f8831fdb9587c9262a344a14
name: 830780E5F8831FDB9587C9262A344A14.mlw
sha1: 0553d3592213ca811f7a2d57aa5dd0e9628f354e
sha256: f1a38307d532d23d85cee2f93a06bcbca7821fe34021f08f38db19cb57531b53
sha512: cf5d99fa71cdae2f679fd704174b53c962a621ecb23667d77cb42e28befbedb85c71c503616f513a4f837b658e69b47194b662caf758f0bba542b6200b09d7e3
ssdeep: 6144:DO6jC44pLGVaZC+KvbGMOEBIxvndfJFSFR:DBjC4mLGVaZYdd6hG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2014 VMware, Inc.
InternalName: xferlogs
FileVersion: 9.6.2.31837
CompanyName: VMware, Inc.
ProductName: VMware Tools
ProductVersion: 9.6.2 build-1688356
FileDescription: VMware xferlogs Utility
OriginalFilename: xferlogs.exe
Translation: 0x0409 0x04b0

Trojan.Ransom.Cerber.QX also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.830780e5f8831fdb
CAT-QuickHealRansom.Cerber.A4
McAfeeRansomware-CBER!830780E5F883
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zerber.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005224381 )
BitDefenderTrojan.Ransom.Cerber.QX
K7GWTrojan ( 005224381 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Ransom.Cerber.QX
CyrenW32/Cerber.F.gen!Eldorado
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Zerber.eoefex
MicroWorld-eScanTrojan.Ransom.Cerber.QX
RisingTrojan.Kryptik!8.8 (C64:YzY0Ogq916wO5YnY)
Ad-AwareTrojan.Ransom.Cerber.QX
SophosML/PE-A + Mal/Cerber-B
ComodoTrojWare.Win32.Ransom.Cerber.FTV@75b3ao
F-SecureHeuristic.HEUR/AGEN.1121405
DrWebTrojan.Encoder.11198
ZillyaTrojan.Zerber.Win32.2140
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionBehavesLike.Win32.Ransomware.fh
EmsisoftTrojan.Ransom.Cerber.QX (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ebnar
AviraHEUR/AGEN.1121405
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Cerber
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.QX
AhnLab-V3Win-Trojan/Cerber.Exp
Acronissuspicious
BitDefenderThetaAI:Packer.4F5936EC1F
ALYacTrojan.Ransom.Cerber.QX
TACHYONRansom/W32.Cerber.367616.B
VBA32BScope.Backdoor.Vawtrak
MalwarebytesMalware.AI.2543119830
PandaTrj/Genetic.gen
ESET-NOD32Win32/Filecoder.Cerber.G
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
TencentMalware.Win32.Gencirc.10b1efbb
YandexTrojan.GenAsa!7UIOQEE3ciU
IkarusTrojan.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HGZD!tr
WebrootW32.Ransom.Gen
AVGWin32:Malware-gen
Cybereasonmalicious.5f8831
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.RansomeCerber.HxQBgOIA

How to remove Trojan.Ransom.Cerber.QX?

Trojan.Ransom.Cerber.QX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment