Ransom Trojan

Trojan-Ransom.NSIS.Zerber removal guide

Malware Removal

The Trojan-Ransom.NSIS.Zerber is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.NSIS.Zerber virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.NSIS.Zerber?


File Info:

crc32: FBA8A78E
md5: 0959d7f3742179485aec77a13b80451d
name: 0959D7F3742179485AEC77A13B80451D.mlw
sha1: a092a0de3311aff6e4fa52d2dc933090c67d511f
sha256: 13829ea7e3b106031ba2c36972ba84ed73751dca9d3d034a0aa302c472a5971b
sha512: 93f5a16d4d1c597fed8179bc817e0630c59e4994f0bdf1d4bf6eb3edf9f7ecd44c5947f8a904d9d9cc8f740add7321efefcafc7898f38454210e5ce7e2b38cc5
ssdeep: 3072:GNdm6/Xbi5XJC/O45RzVuXXnoMrbe2JH+uCMatInkIBJ00ISgxXpixQw+WSw/KN:Gn/L+GOmzE4MrbXBLaikIBJ0tSEX6+Qo
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.NSIS.Zerber also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3f51 )
LionicTrojan.NSIS.Generic.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Click3.25793
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.3003276
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 0055e3f51 )
Cybereasonmalicious.374217
CyrenW32/Cerber.ZXKZ-6074
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Cerber-9845751-0
KasperskyHEUR:Trojan-Ransom.NSIS.Zerber.gen
BitDefenderTrojan.NSIS.Androm.11
NANO-AntivirusTrojan.Win32.Panda.ehxjtd
MicroWorld-eScanTrojan.NSIS.Androm.11
TencentWin32.Trojan.Raasj.Auto
SophosMal/Generic-R + Mal/Miuref-L
ComodoMalware@#2npm1usl9qpqu
F-SecureHeuristic.HEUR/AGEN.1120699
BitDefenderThetaGen:NN.ZedlaF.34110.lC8@auDqNGe
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SMNSX
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.cc
FireEyeGeneric.mg.0959d7f374217948
EmsisoftTrojan.NSIS.Androm.11 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Ransom
AviraHEUR/AGEN.1124303
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Miuref.R
ArcabitTrojan.Generic.D2DD38C
SUPERAntiSpywareRansom.Cerber/Variant
ZoneAlarmHEUR:Trojan-Ransom.NSIS.Zerber.gen
GDataTrojan.GenericKD.3003276
AhnLab-V3Trojan/Win32.Miuref.R189513
McAfeeRDN/Generic.bds
MAXmalware (ai score=100)
VBA32Trojan.Click
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPCERBER.SMNSX
RisingTrojan.Generic@ML.91 (RDML:08seR6qkxuqHAQu8TvZD0g)
YandexTrojan.GenAsa!rCXNmI7/ldk
FortinetW32/InjectorGen.DGRI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.NSIS.Zerber?

Trojan-Ransom.NSIS.Zerber removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment