Ransom Trojan

Should I remove “Trojan-Ransom.Win32.Zerber.dhfg”?

Malware Removal

The Trojan-Ransom.Win32.Zerber.dhfg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Zerber.dhfg virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.blockcypher.com
hjhqmbxyinislkkt.1j9r76.top

How to determine Trojan-Ransom.Win32.Zerber.dhfg?


File Info:

crc32: AE47B274
md5: d4db22722bc627c09e274f7ef968e505
name: D4DB22722BC627C09E274F7EF968E505.mlw
sha1: a8a322a6e0e8f3ec5343c49fd7999e6b3ba9b510
sha256: 39013f3ab8192a09accc6efd9c22b0a244c321e5a1185aa8d1a8a9ecb41f0fa7
sha512: eed7151128602de704a8aa507e0f99b7e10ac9ddd4b5eae5715c684836c0b9d84362a9c7b0f6af6a5ad37af94332de8eb8b0406123845f16e43dacb3f2dcc2f8
ssdeep: 6144:udU/vqqwJ+c5GRkKTDsU+cn+Ui+HApZmBBh:udU3NZc5GkIITR+gWBBh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Zerber.dhfg also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00515aa21 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.A3
ALYacTrojan.GenericKDZ.38646
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.1588
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00515aa21 )
Cybereasonmalicious.22bc62
CyrenW32/Nymaim.BZ.gen!Eldorado
SymantecPacked.Generic.493
ESET-NOD32Win32/Filecoder.Cerber.I
APEXMalicious
AvastWin32:Filecoder-AY [Trj]
ClamAVWin.Ransomware.Cerber-9770533-1
KasperskyTrojan-Ransom.Win32.Zerber.dhfg
BitDefenderTrojan.GenericKDZ.38646
NANO-AntivirusTrojan.Win32.Zerber.eppjyv
MicroWorld-eScanTrojan.GenericKDZ.38646
TencentMalware.Win32.Gencirc.10ba9b69
Ad-AwareTrojan.GenericKDZ.38646
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Crypt.C@7vajd0
BitDefenderThetaGen:NN.ZexaF.34790.qqX@amFVO2g
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.d4db22722bc627c0
EmsisoftTrojan.GenericKDZ.38646 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.bex
AviraHEUR/AGEN.1120889
eGambitUnsafe.AI_Score_99%
ArcabitTrojan.Generic.D96F6
AegisLabTrojan.Win32.Zerber.j!c
GDataTrojan.GenericKDZ.38646
AhnLab-V3Trojan/Win32.Cerber.R197596
Acronissuspicious
McAfeeRansomware-FMJ!D4DB22722BC6
MAXmalware (ai score=100)
VBA32BScope.Trojan-Ransom.Zerber
MalwarebytesRansom.Cerber
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SM37
RisingRansom.GlobeImposter!1.AF70 (CLASSIC)
YandexTrojan.GenAsa!4D4AAO3qGHQ
IkarusTrojan-Ransom.Cerber
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FSHI!tr
AVGWin32:Filecoder-AY [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBEpsA

How to remove Trojan-Ransom.Win32.Zerber.dhfg?

Trojan-Ransom.Win32.Zerber.dhfg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment