Ransom Trojan

Trojan-Ransom.Win32.Zerber.fklk malicious file

Malware Removal

The Trojan-Ransom.Win32.Zerber.fklk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Zerber.fklk virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Zerber.fklk?


File Info:

crc32: C01DA0B0
md5: a640d1588d1cbe47b56b00ab43c88e4f
name: A640D1588D1CBE47B56B00AB43C88E4F.mlw
sha1: 3cdc7671f4e8769dce6495fd7695273880dce1f8
sha256: ce7f6569bb1de5bc811f4233bfd5accf553576cafe17494c652093a687e5488a
sha512: b290e7f66fa1a75df6331fe40aea11b9d6a15b0f3166327cc1cb1d93948b1d4a6658e7f71a9be022a342033e6cb77f288d692dd1372ceaa2ee527344379159da
ssdeep: 24576:nlIe0JLjAPbEN1/UcVHCcHQBnDN9PQek5ZADFYZ9SUMNjM+0P:UJLjkof/l1FwBDN9YO+7MW
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Zerber.fklk also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 00528af51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Jaik.42036
CylanceUnsafe
ZillyaAdware.Hpdefender.Win32.24
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Zerber.2a9ea905
K7GWAdware ( 00528af51 )
Cybereasonmalicious.88d1cb
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyTrojan-Ransom.Win32.Zerber.fklk
BitDefenderGen:Variant.Jaik.42036
NANO-AntivirusRiskware.Win32.Hpdefender.eylrse
MicroWorld-eScanGen:Variant.Jaik.42036
TencentWin32.Trojan.Zerber.Llgq
Ad-AwareGen:Variant.Jaik.42036
SophosGeneric PUA DM (PUA)
ComodoApplicUnwnt@#1h09623abxvg1
BitDefenderThetaGen:NN.ZexaF.34126.YyW@aSA!E8li
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.ICLoader.tc
FireEyeGeneric.mg.a640d1588d1cbe47
EmsisoftGen:Variant.Jaik.42036 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117983
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.24B17C2
KingsoftWin32.Troj.Hpdefender.wn.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Jaik.42036
McAfeeICLoader
MAXmalware (ai score=100)
VBA32Adware.Presenoker
MalwarebytesMalware.AI.1202724719
PandaTrj/CI.A
RisingTrojan.Generic@ML.92 (RDML:JL0Wfl3Dfyg0ZY1upjNxHA)
YandexTrojan.GenAsa!fnFTtOMe9yo
FortinetRiskware/HPDefender
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Zerber.fklk?

Trojan-Ransom.Win32.Zerber.fklk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment