Ransom Trojan

What is “Trojan-Ransom.Win32.Zerber.eycu”?

Malware Removal

The Trojan-Ransom.Win32.Zerber.eycu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Zerber.eycu virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Zerber.eycu?


File Info:

crc32: 38F28D3C
md5: c3d61ea24268e5b4ccb2edac5b7bf91c
name: C3D61EA24268E5B4CCB2EDAC5B7BF91C.mlw
sha1: 01befb5b6a2daa07f15ba690fdfd39b4ba0ad94b
sha256: a1ba73ea0920894da5800b53744751a31293d37b0cd1dd1005d02a1aaa600618
sha512: fdb6e1ea4ed9ca24063334976c2f40b0637a50690bde8ddb2d07fa290564699fed8ded400c65edabf81fb6b3aeeff64f8d4575757f759d31a8852a12a3ec7444
ssdeep: 6144:9W+7+eMWvmEtURUqd+asjJ5O+8avjhLPXinSk/Rm:9R1vrU6wk8abxtkZm
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Zerber.eycu also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.43253
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.B
ALYacGen:Heur.NSIS.Cerber.2
CylanceUnsafe
SangforRansom.Win32.Zerber.eycu
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.24268e
CyrenW32/Trojan.KVCU-2269
SymantecRansom.Cerber
ESET-NOD32NSIS/Injector.SJ
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Cerber-9778901-0
KasperskyTrojan-Ransom.Win32.Zerber.eycu
BitDefenderGen:Heur.NSIS.Cerber.2
NANO-AntivirusTrojan.Nsis.Zerber.elfdwm
MicroWorld-eScanGen:Heur.NSIS.Cerber.2
TencentWin32.Trojan.Raas.Auto
SophosML/PE-A + Mal/Cerber-AA
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.dc
FireEyeGeneric.mg.c3d61ea24268e5b4
EmsisoftGen:Heur.NSIS.Cerber.2 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Dropper.Gen
MicrosoftRansom:Win32/Cerber!rfn
GDataGen:Heur.NSIS.Cerber.2
AhnLab-V3Trojan/Win32.Cerber.R194435
McAfeeArtemis!C3D61EA24268
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Zerber
PandaTrj/CI.A
FortinetW32/Injector.SQ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HyoDEpsA

How to remove Trojan-Ransom.Win32.Zerber.eycu?

Trojan-Ransom.Win32.Zerber.eycu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment