Trojan

Trojan:Win32/Cerber!pz information

Malware Removal

The Trojan:Win32/Cerber!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cerber!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine Trojan:Win32/Cerber!pz?


File Info:

name: 9F8D563C50A319304B95.mlw
path: /opt/CAPEv2/storage/binaries/6c124239f16dbf21d312916525da0caaac2c7794a69508c27925eb247d128b70
crc32: C4AB16C7
md5: 9f8d563c50a319304b9532e762ad5531
sha1: 0fb1d4bd1ccf2f4a873447c6f1adf6d1b2d22e51
sha256: 6c124239f16dbf21d312916525da0caaac2c7794a69508c27925eb247d128b70
sha512: 09822b588d6dc4258c8dcf9bbbe1aea3d40c0939389a5015fb13fda5bb7722b36cbe1804314a0ef354194de026c898ac69aa13f0574d8be169b2f50fc5a6eed1
ssdeep: 1536:hnbeGe8mQQWYtbrms9f/iDjWNHYU22LQS5DUHRbPa9b6i+sI:lbevVas9CDyRRbQS5DSCopsI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154447C4B67234FB2F19602F5015A8484F2E95BEE2F75CE94146CC1560B33B58CA7FBA2
sha3_384: dfefcb89d143733fd116c65a3135b2c9e6798d9ae54205fd0975c0339ca76dc1539c8a37985794391b351377803e4d92
ep_bytes: 00000000000000000000000000000000
timestamp: 1987-01-13 04:22:33

Version Info:

0: [No Data]

Trojan:Win32/Cerber!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
ClamAVWin.Dropper.Berbew-10009572-0
FireEyeGeneric.mg.9f8d563c50a31930
SkyhighBehavesLike.Win32.Generic.dz
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Convagent.Win32.506846
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Cerber.88e0d95c
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Convagent.gen
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.13fe53f5
SophosMal/Generic-S
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Siggen13.57251
TrendMicroTROJ_GEN.R03BC0DAL24
Trapminesuspicious.low.ml.score
IkarusTrojan.Crypt
GDataWin32.Trojan.Agent.CK5BZX
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
KingsoftWin32.Trojan.Convagent.gen
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Cerber!pz
VaristW32/Padodor.F.gen!Eldorado
McAfeeGenericRXVP-WI!9F8D563C50A3
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DAL24
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.HTI!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.d1ccf2
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Cerber!pz?

Trojan:Win32/Cerber!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment