Malware

Win32/Filecoder.Cerber.Z removal instruction

Malware Removal

The Win32/Filecoder.Cerber.Z is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Cerber.Z virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Checks for the presence of known devices from debuggers and forensic tools
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Filecoder.Cerber.Z?


File Info:

name: DF4E5C6775C14E72FA41.mlw
path: /opt/CAPEv2/storage/binaries/eba0482a5b1232db451b1a745dd8e99defb9f1194b070e2f5c20eeb251296a86
crc32: 1F38B0E1
md5: df4e5c6775c14e72fa41bce9b91755f8
sha1: a42413c50f56e92ccba47f62eea44bb9542199d8
sha256: eba0482a5b1232db451b1a745dd8e99defb9f1194b070e2f5c20eeb251296a86
sha512: 8152f07a6234385bb2a83300a6e9d410cbe392ce271d1de6d8196cb09fe4b3bdc68279c8d0ff41839a679174a1a088d7919c253f49794bee1368f0775ba75f9d
ssdeep: 12288:84GTI/cvffub6u4iRFJmVX5h4lij0m+t+OeO+OeNhBBhhBB/quZplAcyOdvo+nwk:84y+UXquZf7Zvo+nvAYVD3
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T186F49D32B7D3E173D99224F04D2DA75E2839F82A0B295BE7B3D41B2E4A701D24E3165D
sha3_384: 4f5b311aef6eccc1fcf278f74b22f13542fe9710fab21a8de79ecfc337de35ff293c96cb1248859ed9faa3ee4d37559b
ep_bytes: e881800000e995feffffcccccccccccc
timestamp: 2021-12-04 12:14:46

Version Info:

0: [No Data]

Win32/Filecoder.Cerber.Z also known as:

LionicTrojan.Win32.Ferber.j!c
DrWebTrojan.Encoder.34693
MicroWorld-eScanTrojan.GenericKD.38215411
FireEyeTrojan.GenericKD.38215411
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
SangforTrojan.Win32.Cerber.Z
K7AntiVirusTrojan ( 0058b9801 )
AlibabaRansom:Win32/Cerber.5a741733
K7GWTrojan ( 0058b9801 )
CyrenW32/Trojan.IXCC-5332
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Cerber.Z
TrendMicro-HouseCallRansom.Win32.LOCKERGOGA.SM1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderTrojan.GenericKD.38215411
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.11ddb1d0
Ad-AwareTrojan.GenericKD.38215411
SophosMal/Generic-S
ZillyaTrojan.Filecoder.Win32.21094
TrendMicroRansom.Win32.LOCKERGOGA.SM1
McAfee-GW-EditionBehavesLike.Win32.PUPXBV.bh
EmsisoftTrojan.GenericKD.38215411 (B)
GDataTrojan.GenericKD.38215411
JiangminTrojan.Crypren.adq
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Ransom.Cerber.qhspm
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.34E8FCE
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Mamson.A!ac
CynetMalicious (score: 99)
AhnLab-V3Ransomware/Win.LOCKERGOGA.C4818009
McAfeeRDN/Ransom
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesRansom.FileCryptor
APEXMalicious
RisingRansom.Ferber!8.1304D (CLOUD)
YandexTrojan.Filecoder!Ihhz7AQyl/w
IkarusTrojan-Ransom.Cerber
FortinetW32/Ransom_Win32_LOCKERGOGA.SM1
WebrootW32.Trojan.Gen
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Filecoder.Cerber.Z?

Win32/Filecoder.Cerber.Z removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment