Ransom

Ransom.Cerber.ZZ4 (file analysis)

Malware Removal

The Ransom.Cerber.ZZ4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Cerber.ZZ4 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Cerber.ZZ4?


File Info:

crc32: 840567A2
md5: 8199556b656e0d8213371d610e129236
name: 8199556B656E0D8213371D610E129236.mlw
sha1: 08e652c4d34eaf442e0f5369b8e7703f54c1c206
sha256: 58b051791722916e76beab4133fd0e9911dea0db49583aaac2b4dacadc336847
sha512: 506b4beb5cf4380974f8f9c98870b9777ec299826fa23fdb951883dc804ff3c594c4968e86c2fdbbd35777147ae1d0a724e8be06293af9eb4d49f2980187d85b
ssdeep: 6144:93STJ/7QDRy7QJ8Z4/9PddxExSctttjsQN0Tav6uFz2LJGRg4kLNnei36cw:kTJ/7rQQC9VjE4M30WJFCdUc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: sethc.exe
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: Accessibility shortcut keys
OriginalFilename: sethc.exe
Translation: 0x0409 0x04b0

Ransom.Cerber.ZZ4 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00517c481 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.ZZ4
ALYacTrojan.Mint.Zamg.O
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.3813
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.edc76010
K7GWTrojan ( 00514fc51 )
Cybereasonmalicious.b656e0
CyrenW32/Trojan.FOT.gen!Eldorado
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Kryptik.FVSW
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Mint.Zamg.O
NANO-AntivirusTrojan.Win32.Encoder.etdllo
MicroWorld-eScanTrojan.Mint.Zamg.O
TencentMalware.Win32.Gencirc.10bae450
Ad-AwareTrojan.Mint.Zamg.O
SophosML/PE-A + Mal/Cerber-AL
ComodoTrojWare.Win32.Bulta.GR@7k46qi
BitDefenderThetaGen:NN.ZexaF.34608.Fq0@a0lMokbi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SMALY5B
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.mg.8199556b656e0d82
EmsisoftTrojan.Mint.Zamg.O (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129194
eGambitUnsafe.AI_Score_92%
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Mint.Zamg.O
GDataWin32.Trojan-Ransom.Cerber.AL
TACHYONRansom/W32.Cerber.513536.B
AhnLab-V3Win-Trojan/RansomCrypt.Gen
Acronissuspicious
McAfeeRansomware-GCQ!8199556B656E
MAXmalware (ai score=99)
VBA32Trojan-Ransom.Zerber
MalwarebytesMalware.AI.2562829596
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SMALY5B
RisingTrojan.Kryptik!1.AD41 (CLOUD)
IkarusTrojan.Crypt
FortinetW32/Zamg.O!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HxQBQpEA

How to remove Ransom.Cerber.ZZ4?

Ransom.Cerber.ZZ4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment