Ransom Trojan

About “Trojan.Ransom.Cerber” infection

Malware Removal

The Trojan.Ransom.Cerber is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ransom.Cerber?


File Info:

crc32: 78AAA139
md5: 0027ec786e5e476d88ed5f2aab27829e
name: 0027EC786E5E476D88ED5F2AAB27829E.mlw
sha1: 9d47aa2e07d4b18aa1868527af95103c2510e363
sha256: 4e833eeae662467210dc690c77becc4bd46773e41112502a481c759c7803681c
sha512: 3d1250ad6cf54305228d9f254ad6b3d0ce157561fa9a6f207ea2478952587b847f80c8195e8354ba65dc9fd931e8b46d7c139d43f3a050ad762e28254e3afb76
ssdeep: 6144:CZA9PSWCfUxuNuUelUa4Z/uIjhXOmqGWQnLOpv29ruo+jPRNLIaj8X:n9KWCNbn/dZ89Ma+R+jIaIX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2015
InternalName: SmartRAM
FileVersion: 9.0.0.22
CompanyName: IObit
LegalTrademarks: IObit
Comments: Smart RAM
ProductName: Smart RAM
ProductVersion: 9.0.0.0
FileDescription: Monitors and Optimizes memory usage to increase available physical memory.
OriginalFilename: SmartRAM.exe
Translation: 0x0409 0x04e4

Trojan.Ransom.Cerber also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Mint.Zamg.O
FireEyeGeneric.mg.0027ec786e5e476d
CAT-QuickHealRansom.Cerber.A4
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054f2ec1 )
BitDefenderTrojan.Mint.Zamg.O
K7GWTrojan ( 00514a871 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Cerber.BF.gen!Eldorado
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-9760825-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.b6d5d009
NANO-AntivirusTrojan.Win32.Zerber.eryrsr
ViRobotTrojan.Win32.Cerber.509440.B
RisingTrojan.Kryptik!1.AD41 (CLOUD)
Ad-AwareTrojan.Mint.Zamg.O
EmsisoftTrojan.Mint.Zamg.O (B)
ComodoTrojWare.Win32.Zonidel.AY@7kn16e
F-SecureHeuristic.HEUR/AGEN.1128809
ZillyaTrojan.Kryptik.Win32.2318032
TrendMicroRansom_HPCERBER.SMALY5B
McAfee-GW-EditionRansomware-GCQ!0027EC786E5E
MaxSecureWin.MxResIcn.Heur.Gen
SophosML/PE-A + Mal/Cerber-AL
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Generic.eahhp
AviraHEUR/AGEN.1128809
MAXmalware (ai score=100)
MicrosoftRansom:Win32/Cerber.L!bit
ArcabitTrojan.Mint.Zamg.O
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.Cerber.AL
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Cerber.Exp
Acronissuspicious
McAfeeRansomware-GCQ!0027EC786E5E
TACHYONRansom/W32.Cerber.509440.T
VBA32BScope.Trojan.Encoder
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FVYF
TrendMicro-HouseCallRansom_HPCERBER.SMALY5B
TencentMalware.Win32.Gencirc.10b58b67
YandexTrojan.GenAsa!9GVqn+7th0g
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Zamg.O!tr
BitDefenderThetaGen:NN.ZexaF.34590.Fq0@aO4mc@aj
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQBPPsA

How to remove Trojan.Ransom.Cerber?

Trojan.Ransom.Cerber removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment