Ransom Trojan

Trojan.Ransom.Cerber.WZ removal tips

Malware Removal

The Trojan.Ransom.Cerber.WZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.WZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to remove evidence of file being downloaded from the Internet
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ransom.Cerber.WZ?


File Info:

crc32: 99C14AA0
md5: 0a8bafbc3c87ec070c1ec7a28b915761
name: 0A8BAFBC3C87EC070C1EC7A28B915761.mlw
sha1: ae4764f43fbdde9509000ec4a35c50c31992da98
sha256: 1e6810547ddaa4f01cb898d64f88dfd3ab1d5b08382001dfb6e1c20760cf4ed3
sha512: 224bf1c3cfb4a08721934f2a9a870cca21e80c0baf2e1718ba9e385fa8d4754b5a205a761f77b55a1b0651ad8e03bbad124391cca84e74bf125aa611497c0893
ssdeep: 1536:r2NEtEOLgqgBNbcZpGqvDNDCA7/lSrXda2TGy7EZ++pd:aggFeGW+WQXdtr7G/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.Cerber.WZ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10103
MicroWorld-eScanTrojan.Ransom.Cerber.WZ
FireEyeGeneric.mg.0a8bafbc3c87ec07
CAT-QuickHealTrojan.Generic
McAfeeRansomware-GBQ!0A8BAFBC3C87
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005137001 )
BitDefenderTrojan.Ransom.Cerber.WZ
K7GWTrojan ( 005106051 )
Cybereasonmalicious.c3c87e
BitDefenderThetaGen:NN.ZexaF.34590.gqX@aWpgd4b
CyrenW32/Nymaim.BZ.gen!Eldorado
SymantecPacked.Generic.493
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Generic-6329920-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Spora.e8aeb23c
NANO-AntivirusTrojan.Win32.Encoder.eqlxtb
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Kryptik!1.AB95 (CLOUD)
Ad-AwareTrojan.Ransom.Cerber.WZ
EmsisoftTrojan.Ransom.Cerber.WZ (B)
ComodoTrojWare.Win32.Crypt.C@7vajd0
F-SecureHeuristic.HEUR/AGEN.1116789
ZillyaTrojan.Kryptik.Win32.1213113
TrendMicroRansom_CERBER.SM38
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
SophosML/PE-A + Mal/Elenoocka-E
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Generic.bbrrk
AviraHEUR/AGEN.1116789
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Spora
ArcabitTrojan.Ransom.Cerber.WZ
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.WZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.R202918
Acronissuspicious
VBA32Hoax.Spora
ALYacTrojan.Ransom.Cerber.WZ
TACHYONRansom/W32.Spora.108464
MalwarebytesMalware.Heuristic.1001
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FTPB
TrendMicro-HouseCallRansom_CERBER.SM38
TencentMalware.Win32.Gencirc.10b2feb8
YandexTrojan.GenAsa!HEz3n+vwXgw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/GenKryptik.APXF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Sorter.AVE.Etap.A

How to remove Trojan.Ransom.Cerber.WZ?

Trojan.Ransom.Cerber.WZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment