Trojan

Trojan:Win32/Cerber!pz removal

Malware Removal

The Trojan:Win32/Cerber!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cerber!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Cerber!pz?


File Info:

name: F9C828E5F456C2D67A37.mlw
path: /opt/CAPEv2/storage/binaries/2b489042019f531d495ca9772768e97d60e6cb16e65b1147075eafa973352d14
crc32: F517A137
md5: f9c828e5f456c2d67a37742be8111a37
sha1: be9d40bfea5b1e913c4f4ea9f893c8039c2b0a52
sha256: 2b489042019f531d495ca9772768e97d60e6cb16e65b1147075eafa973352d14
sha512: 60a0f4aa737b3bcc25a01cf3e3a582c4e2db0832709fb5fd53a9de328266a551e41342a0d944d7a736d2b71d3770adf94598834bfdf9be60d262e749c44b6a67
ssdeep: 1536:84WwSg0LozQnjAOSNv2yk7fuD6mAPgnDNBrcN4i6tBYuR3PlNPMAZ:84hSg0LwcjA/Qy3D6mAPgxed6BYudlNd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6A34B9B7BE51FBEC24203B5246F49D2F32AD0E953AA958014A9C21D137BD588277FC3
sha3_384: 8df07b2a5b55ac338b43a8bff78224e6f8e97dde73471a205253831d981df926edefae3dabe6063a1b33cd45ebda5012
ep_bytes: 90909060909090b8001040009090906a
timestamp: 2018-07-09 22:06:51

Version Info:

0: [No Data]

Trojan:Win32/Cerber!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43791
MicroWorld-eScanDropped:Backdoor.Padodor.BJ
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.nh
McAfeeTrojan-FVOJ!F9C828E5F456
MalwarebytesGeneric.Malware.AI.DDS
VIPREDropped:Backdoor.Padodor.BJ
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.fea5b1
BitDefenderThetaAI:Packer.296DA1BE21
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
ClamAVWin.Trojan.Crypted-29
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderDropped:Backdoor.Padodor.BJ
NANO-AntivirusTrojan.Win32.GenKryptik.kcaizj
AvastWin32:TrojanX-gen [Trj]
EmsisoftDropped:Backdoor.Padodor.BJ (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
BaiduWin32.Trojan-Spy.Quart.a
ZillyaTrojan.PadodorGen.Win32.1
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f9c828e5f456c2d6
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=89)
GDataWin32.Trojan.PSE.11RRK8R
JiangminTrojan.Generic.dzrgt
GoogleDetected
AviraTR/Crypt.XDR.Gen
VaristW32/Agent.HJI.gen!Eldorado
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitBackdoor.Padodor.BJ
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
MicrosoftTrojan:Win32/Cerber!pz
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacDropped:Backdoor.Padodor.BJ
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Cerber!pz?

Trojan:Win32/Cerber!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment