Ransom Trojan

Trojan-Ransom.Win32.Zerber.dako removal instruction

Malware Removal

The Trojan-Ransom.Win32.Zerber.dako is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Zerber.dako virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

api.blockcypher.com
btc.blockr.io
bitaps.com
chain.so
ocsp.digicert.com
p27dokhpz2n7nvgr.1j9r76.top

How to determine Trojan-Ransom.Win32.Zerber.dako?


File Info:

crc32: 14FFD181
md5: 6a982f51e3ab9dca1dd3a624cc520988
name: 6A982F51E3AB9DCA1DD3A624CC520988.mlw
sha1: f8e62744edcaa839ffeeab911a594438d6be744d
sha256: d1a6e0e2dc7beb38678da94d7a14d6fe3ee3fc0d941e91b57f3eb807f2088035
sha512: cb9b217e615fb317b591eee96d449c8af4e654a47525f21e12d4d11760fdd93c5eea8cb3c18a8f25c6b9d08ab96effc6edc066773ad988d3c7a57f4177871cb8
ssdeep: 6144:H28A9Mmeh5PNJTEM9akV3jt95bx3nzBUi:W8LnQk9jlbRzB/
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Zerber.dako also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0050885a1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10464
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.4597313
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.66620
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0050885a1 )
Cybereasonmalicious.1e3ab9
CyrenW32/Cerber.LHNA-7575
SymantecRansom.Wannacry
ESET-NOD32a variant of Win32/Injector.DMLC
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-6987220-0
KasperskyTrojan-Ransom.Win32.Zerber.dako
BitDefenderTrojan.GenericKD.4597313
MicroWorld-eScanTrojan.GenericKD.4597313
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKD.4597313
SophosML/PE-A + Mal/Cerber-Z
ComodoMalware@#276ms94r05flk
BitDefenderThetaGen:NN.ZedlaF.34142.cq4@aGJ!Bdk
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0PG621
McAfee-GW-EditionBehavesLike.Win32.ICLoader.dc
FireEyeGeneric.mg.6a982f51e3ab9dca
EmsisoftTrojan-Ransom.Cerber (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Zerber.eez
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1116898
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.33DE9F1
KingsoftWin32.Troj.Generic.v.(kcloud)
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Generic.D462641
ZoneAlarmTrojan-Ransom.Win32.Zerber.dako
GDataTrojan.GenericKD.4597313
TACHYONRansom/W32.Cerber.236305
AhnLab-V3Trojan/Win32.Cerber.R196732
McAfeeArtemis!6A982F51E3AB
MAXmalware (ai score=100)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R011C0PG621
YandexTrojan.Injector!YVeOSF8MKqo
FortinetW32/Injector.DMTB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Zerber.dako?

Trojan-Ransom.Win32.Zerber.dako removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment