Trojan

Trojan:Win32/Cerber!pz (file analysis)

Malware Removal

The Trojan:Win32/Cerber!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cerber!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Trojan:Win32/Cerber!pz?


File Info:

name: E9D16F4DD858A97704EC.mlw
path: /opt/CAPEv2/storage/binaries/c70e474c603319e66d8b4ba692da4b092df6abcfcef25da539fc99f522b6b418
crc32: 2F6F87C3
md5: e9d16f4dd858a97704ec0322de7a6201
sha1: 06f72510b9b00dabcbae6759dd32192a50d04172
sha256: c70e474c603319e66d8b4ba692da4b092df6abcfcef25da539fc99f522b6b418
sha512: f235dd23f14e197113fd21b6a6c0f79904ed438831302bc373da936258317217634e5c1b52a65e4cf944eb79069be46fa549154eb8309643692c95e3a6d5fb5b
ssdeep: 768:DmSheguntEpPncsbuIGdiPltBAwhGkqDaR7A1t5kAJYJB/XCRg1Q52p/1H5TyXdo:DmShePtanLJBPhVq/CAJUFA2LlYO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD24290DE8BB9DBAC468027D41AF796CD2E64C89F6A6B084533FE3CC775305459E4A38
sha3_384: 8f25a52235542165e48e0ea46d186aaa62f3ec6c87d49e0806aebd232731c5597260a29e03032d791153ec7582214967
ep_bytes: 00000000000000000000000000000000
timestamp: 1984-04-18 04:22:33

Version Info:

0: [No Data]

Trojan:Win32/Cerber!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Berbew.m!c
FireEyeGeneric.mg.e9d16f4dd858a977
SkyhighBehavesLike.Win32.Generic.dz
McAfeeGenericRXAA-FA!E9D16F4DD858
Cylanceunsafe
ZillyaBackdoor.Convagent.Win32.34648
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaBackdoor:Win32/Berbew.88caffa9
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Spy.Quart.a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Qukart-6838239-0
KasperskyHEUR:Backdoor.Win32.Convagent.gen
NANO-AntivirusTrojan.Win32.Convagent.kiihtz
AvastWin32:Evo-gen [Trj]
SophosMal/Generic-S
DrWebTrojan.Siggen13.57251
TrendMicroTROJ_GEN.R03BC0DAT24
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Cerber!pz
ZoneAlarmHEUR:Backdoor.Win32.Convagent.gen
GDataWin32.Trojan.Agent.CB730E
VaristW32/Heuristic-CO3!Eldorado
AhnLab-V3Trojan/Win.Cerber.C5536033
Acronissuspicious
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0DAT24
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusBackdoor.Win32.Berbew
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.3E08!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.0b9b00
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Cerber!pz?

Trojan:Win32/Cerber!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment