Ransom Trojan

Trojan-Ransom.Win32.Zerber.fjca removal guide

Malware Removal

The Trojan-Ransom.Win32.Zerber.fjca is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Zerber.fjca virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Zerber.fjca?


File Info:

crc32: C480F01D
md5: b0dc6f0f11d613e00ba65dd762d12e88
name: B0DC6F0F11D613E00BA65DD762D12E88.mlw
sha1: cd4f8b2d039978bd7949fcad73f17009857692d9
sha256: fb8c07648ba66a4840428c7d1bf165da505765fa801a70d2b3f5fdaa63724684
sha512: 65dde1c0e3efd651ffda30277114c71fb3d37edf607af1a859f08a16787356991862dc8684658ae042ce5e685da82c0d55df59898442ba8cf1fd1f7bc8baf62c
ssdeep: 6144:gpSTvre+9xzp5AD9SRVAnf/XvHPnnfnHnPn/nnnPn3nfn3nvnHn/nnvH3HvPnXnJ:pTTe+7pO9SRtNdpVNA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2015 Lamantine Software a.s.
InternalName: spLauncher
FileVersion: 8.0.4.34
CompanyName: Lamantine Software a.s.
p://www.stickypassword.com: D
LegalTrademarks: >x0bx01OriginalFilename
cky Password: 6 x01ProductVersion
FileDescription: Sticky Password
ass.exe: @x10x01ProductName
.4.34: Tx1ex01Homepage
Translation: 0x0409 0x04e4

Trojan-Ransom.Win32.Zerber.fjca also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealTrojanRansom.Crowti.MUE.A4
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005224381 )
Cybereasonmalicious.f11d61
BaiduWin32.Trojan.Kryptik.avk
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FFSE
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Downloader.Cridex-7586795-0
KasperskyTrojan-Ransom.Win32.Zerber.fjca
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Zerber.evppps
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Zerber.Pfjg
Ad-AwareTrojan.Ransom.Cerber.1
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaGen:NN.ZexaF.34686.rq1@aGkv7Gfi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM3
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.b0dc6f0f11d613e0
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.brkhs
AviraTR/Crypt.EPACK.Gen2
eGambitUnsafe.AI_Score_98%
MicrosoftRansom:Win32/Cerber.A
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Ransom.Win32.Zerber.fjca
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeTrojan-FORN!B0DC6F0F11D6
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.TorrentLocker
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SM3
RisingRansom.Cerber!8.3058 (CLOUD)
IkarusTrojan.Ransom.Cerber
FortinetW32/Kryptik.HEKH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Zerber.fjca?

Trojan-Ransom.Win32.Zerber.fjca removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment