Ransom Trojan

Trojan-Ransom.Win32.Zerber.fkfo removal guide

Malware Removal

The Trojan-Ransom.Win32.Zerber.fkfo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Zerber.fkfo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Zerber.fkfo?


File Info:

crc32: E63B3968
md5: ba5e7f2dfa27301da9d454125e738468
name: BA5E7F2DFA27301DA9D454125E738468.mlw
sha1: ccf9016cdbe302845346d6bcfc609b7577e43d00
sha256: 4ffbaa244014e4f0f8dcf33f4536769539a5f9f0b8ca8429b057698bdea80894
sha512: 769655d68d29076832591b62306ccf59cdf962de766a61585f1420ed0ef798fe4734830a5fcc67382f11c019f1809a66dac7cbb0553bd0f6153ec638fb660021
ssdeep: 6144:O9hMAoBGQiDddA6pBIuYRXqFI6QXiavts7qoGdWLbOBC0+eekTdFyDPjcat:kDD/i5suFtsdGd2b2vODPJ
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: Tonec Inc., Copyright xa9 1999 - 2015
InternalName: IDMGrHlp
FileVersion: 6, 22, 1, 1
CompanyName: Tonec Inc.
LegalTrademarks: Internet Download Manager
Comments: Auxiliary program for Internet Download Manager
ProductName: Internet Download Manager
ProductVersion: 6, 22, 1, 1
FileDescription: Internet Download Manager module
OriginalFilename: IDMGrHlp.EXE
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Zerber.fkfo also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GenericKD.30323999
FireEyeGeneric.mg.ba5e7f2dfa27301d
McAfeeArtemis!BA5E7F2DFA27
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00516ab91 )
BitDefenderTrojan.Ransom.GenericKD.30323999
K7GWTrojan ( 00516ab91 )
Cybereasonmalicious.dfa273
BitDefenderThetaGen:NN.ZexaF.34590.vmuaaymXUXki
SymantecRansom.Cerber
ESET-NOD32a variant of Win32/Kryptik.FWLM
APEXMalicious
AvastFileRepMalware
ClamAVWin.Dropper.Cerber-9779368-0
KasperskyTrojan-Ransom.Win32.Zerber.fkfo
NANO-AntivirusTrojan.Win32.Zerber.eyaxax
RisingTrojan.Kryptik!1.AD41 (CLOUD)
Ad-AwareTrojan.Ransom.GenericKD.30323999
EmsisoftTrojan.Ransom.GenericKD.30323999 (B)
ComodoTrojWare.Win32.Crypt.FH@77yiqv
F-SecureHeuristic.HEUR/AGEN.1119296
DrWebTrojan.Encoder.4691
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosMal/Generic-S
IkarusTrojan-Ransom.Zerber
JiangminTrojan.Zerber.dba
AviraHEUR/AGEN.1119296
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Cerber.L!bit
ArcabitTrojan.Ransom.Generic.D1CEB51F
ZoneAlarmTrojan-Ransom.Win32.Zerber.fkfo
GDataTrojan.Ransom.GenericKD.30323999
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan-Ransom.Zerber
ALYacTrojan.Ransom.GenericKD.30323999
MAXmalware (ai score=97)
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
TencentWin32.Trojan.Zerber.Pgda
YandexTrojan.Zerber!T6CJdCX8VIk
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FYQG!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/Trojan.Ransom.d32

How to remove Trojan-Ransom.Win32.Zerber.fkfo?

Trojan-Ransom.Win32.Zerber.fkfo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment