Ransom Trojan

How to remove “Trojan-Ransom.Win32.Zerber.fjcp”?

Malware Removal

The Trojan-Ransom.Win32.Zerber.fjcp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Zerber.fjcp virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipinfo.io

How to determine Trojan-Ransom.Win32.Zerber.fjcp?


File Info:

crc32: 3BD5AC6B
md5: b4cfd0e2e21e5c5d9a351f166aa58b3f
name: B4CFD0E2E21E5C5D9A351F166AA58B3F.mlw
sha1: 1031fc16b1e2ccfdf369fe01d1d164b801874003
sha256: cd907311a8e1a03e12a9cc6194753df278044e469aa4f60cceb9b860e0f6a829
sha512: 04afd5daa16b877e56f4f856cb5b698eef12b5a13d990d1e3034633b6c82f7a55dc62c3a50ecbbc3b6b25ed76df3039515e5eaf88b759efb38bde139d889467c
ssdeep: 6144:bSvMYirkJtPIvre6amXoCYd6hWDrc13M4Hckc/T1jxGjJd:lYVmSXm9YLIJMFNj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright Geit Sord Pep
InternalName: bedbugs
FileVersion: 3.4
CompanyName: Geit Sord Pep
ProductName: bedbugs rubbishry
ProductVersion: 3.4
FileDescription: bedbugs nuclide weid
OriginalFilename: bedbugs.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Zerber.fjcp also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f27fc1 )
DrWebTrojan.Encoder.4794
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.66021
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004f27fc1 )
Cybereasonmalicious.2e21e5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FACZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.fjcp
BitDefenderGen:Variant.Symmi.66021
NANO-AntivirusTrojan.Win32.Zerber.evpsar
MicroWorld-eScanGen:Variant.Symmi.66021
TencentWin32.Trojan.Zerber.Pgmx
Ad-AwareGen:Variant.Symmi.66021
SophosML/PE-A + Mal/Cerber-C
ComodoMalware@#2g3fr4wsgeoz5
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-GIX!B4CFD0E2E21E
FireEyeGeneric.mg.b4cfd0e2e21e5c5d
EmsisoftGen:Variant.Symmi.66021 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1121409
MicrosoftRansom:Win32/Cerber.A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Symmi.66021
Acronissuspicious
McAfeeRansomware-GIX!B4CFD0E2E21E
MAXmalware (ai score=99)
VBA32Trojan-Ransom.Zerber
PandaTrj/GdSda.A
RisingRansom.Cerber!8.3058 (CLOUD)
YandexTrojan.Zerber!qA4XqTPn/Ak
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Zerber.fjcp?

Trojan-Ransom.Win32.Zerber.fjcp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment