Malware

Should I remove “Win32/Filecoder.Cerber.X”?

Malware Removal

The Win32/Filecoder.Cerber.X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Cerber.X virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • CAPE detected the Cerber malware family
  • Deletes executed files from disk
  • Attempts to access Bitcoin/ALTCoin wallets
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Filecoder.Cerber.X?


File Info:

name: 8BE27646068B17BE7854.mlw
path: /opt/CAPEv2/storage/binaries/7d6b50f979c16f49b2b30ff2eaa50e1af2dd6d38ec47fe9544e9eb3c2f9e4967
crc32: C0463EBC
md5: 8be27646068b17be785401782308aea6
sha1: fdf2db0edcbeba50139fb6bd571abb7194a86c6f
sha256: 7d6b50f979c16f49b2b30ff2eaa50e1af2dd6d38ec47fe9544e9eb3c2f9e4967
sha512: 0df09a11bf6e6ebaf922e01ff8448008d7417b1c73fb3804d2c619a54f85bb99082361672abac807d5e15895c378434de4bd5be70b958d5bcd2b799100ea557d
ssdeep: 3072:vANmFDHlzVrjMPYqVYtkZq13L11xDVsS9ZxQ+Tju8w0gZAsQCXCuQ4Hx1XKl1W8W:I0DHlJrtkg1BB9xL5seH4PKjHZv/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14034E02F75B09CD2EFF40B7560A5C6DC6802E9257B914503AF8F847AAECA6E093F4315
sha3_384: e72692306ac4506030cf3f489c30bc8dc30da4c509f1d16ebf4eeae416097f08438e507bf9abecbabc8f8ec842aca0fc
ep_bytes: 83ec04892c2489e583c4b46a00810424
timestamp: 2016-11-10 12:03:12

Version Info:

0: [No Data]

Win32/Filecoder.Cerber.X also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
DrWebTrojan.Encoder.4691
FireEyeGeneric.mg.8be27646068b17be
CAT-QuickHealRansom.Cerber.S1448055
McAfeeRansomware-GEF!8BE27646068B
MalwarebytesTrojan.MalPack.VAK
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00515a321 )
AlibabaRansom:Win32/Cerber.ea9
K7GWTrojan ( 00515a321 )
Cybereasonmalicious.edcbeb
BitDefenderThetaGen:NN.ZexaF.36196.puW@aSCSepc
CyrenW32/Trojan.BDN.gen!Eldorado
SymantecPacked.Generic.493
Elasticmalicious (high confidence)
ESET-NOD32Win32/Filecoder.Cerber.X
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Cerber-9969539-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Filecoder.eshhue
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b13ad5
F-SecureHeuristic.HEUR/AGEN.1318550
ZillyaTrojan.Kryptik.Win32.1251820
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
SophosMal/Elenoocka-E
IkarusTrojan.Crypt
JiangminTrojan.Zerber.dbm
GoogleDetected
AviraHEUR/AGEN.1318550
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumTrojWare.Win32.Cerber.FVYG@79g2mu
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.R207757
Acronissuspicious
VBA32Trojan-Ransom.Zerber
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMALY0
RisingTrojan.Kryptik!1.AE8F (CLASSIC)
YandexTrojan.GenAsa!rAmCk5j+22E
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GLXU!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Filecoder.Cerber.X?

Win32/Filecoder.Cerber.X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment