Ransom Trojan

Trojan.Ransom.Cerber.UY (B) removal tips

Malware Removal

The Trojan.Ransom.Cerber.UY (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.UY (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.Cerber.UY (B)?


File Info:

crc32: 501602A4
md5: d99b9cacec070a7fb339f1806091f0d8
name: D99B9CACEC070A7FB339F1806091F0D8.mlw
sha1: ca6c4472baff4de643bdc288f43886cf54609e62
sha256: 8b5ffc066af69ea48a356c46e657d7a290b56206d046fd955a8fdb98e431ab52
sha512: f95e977bbc4d7e203cefeceeb2e8fec7a7f4eea7e5f61e6cb6213fdb78e01ffb9d6fc4fa5e02d0d58aafca93463c0fcd20b8b61c10690a49817c9e79bf9d48f8
ssdeep: 12288:B6VRnX1s1ByoW3VwC/6n62Neu/xmIjKoa+888888888888W88888888888:B6VlX6zW3d/662eauB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.Cerber.UY (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0050f4891 )
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.UY
McAfeeRansomware-FMEU!D99B9CACEC07
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.2674
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0050f4891 )
Cybereasonmalicious.cec070
CyrenW32/S-afb0a24e!Eldorado
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.epxybd
TencentMalware.Win32.Gencirc.10b3230e
Ad-AwareTrojan.Ransom.Cerber.UY
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Crypt.C@7vajd0
DrWebTrojan.Encoder.4691
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroRansom_CERBER.SM37
EmsisoftTrojan.Ransom.Cerber.UY (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1116781
Antiy-AVLTrojan[Ransom]/Win32.Zerber
ArcabitTrojan.Ransom.Cerber.UY
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.UY
TACHYONRansom/W32.Cerber.492544
AhnLab-V3Trojan/Win32.Cerber.R201782
Acronissuspicious
VBA32Trojan.FakeAV.01657
MAXmalware (ai score=100)
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBER.SM37
RisingRansom.Cerber!8.3058 (RDMK:cmRtazoPC1PgL4pP5LZHXdtqSrDJ)
YandexTrojan.GenAsa!1+fvJ0QuT+c
IkarusTrojan-Ransom.Zerber
FortinetW32/Kryptik.FSNS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxMB2JsA

How to remove Trojan.Ransom.Cerber.UY (B)?

Trojan.Ransom.Cerber.UY (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment