Adware

About “Adware.Cerbu.74883” infection

Malware Removal

The Adware.Cerbu.74883 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Cerbu.74883 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Adware.Cerbu.74883?


File Info:

name: 4D75697E433A1801E43A.mlw
path: /opt/CAPEv2/storage/binaries/1831508e6533150867c30721bf30d443b116a244d3ea5f2b2a4d513c8ab80111
crc32: 7C1242ED
md5: 4d75697e433a1801e43a9f857624907f
sha1: d90e8d78620bf7a308471136bc6e203457c413d9
sha256: 1831508e6533150867c30721bf30d443b116a244d3ea5f2b2a4d513c8ab80111
sha512: 6b3cbcc2b422a80024b545e2fb34a6f580aa6d8a1d70a96f8fd1d6ea0fd6a499cf13117eaa42b9e33687bf07ff3d7768c25f823416ba8b18ea6362a9cc03abd5
ssdeep: 196608:tXBbN4yNEdbScbXuoC34mx3tXQ0f2fxChpwza/RLsJmPqqc/tyE:be6Ed2cb701Q0f2fQKuhRiX/tt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2A63396A1521934ED3DD6743C1EF8A9634EAC21FEBD90269DEC7F88407D0C68B9DB10
sha3_384: b94b28d6d87d96725d0ce7b3e6c593ff922fdc454b563f87960948149c82da341c1e3e82b1c57f6f2521199c1d07dd70
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: CE Master LLE
FileDescription: QM Server Repair Toolbox Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Adware.Cerbu.74883 also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Adware.Cerbu.74883
FireEyeGen:Variant.Adware.Cerbu.74883
ALYacGen:Variant.Adware.Cerbu.74883
MalwarebytesAdware.DownloadAssistant
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.BP.gen!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Adware.Cerbu.74883
AvastNSIS:Adware-AEK [Adw]
TencentWin32.Trojan.Ekstak.Ojgl
EmsisoftGen:Variant.Adware.Cerbu.74883 (B)
F-SecureHeuristic.HEUR/AGEN.1333117
VIPREGen:Variant.Adware.Cerbu.74883
McAfee-GW-EditionBehavesLike.Win32.PUP.tc
SophosMal/Generic-S
GDataGen:Variant.Adware.Cerbu.74883
JiangminTrojan.Ekstak.bvfi
AviraHEUR/AGEN.1333117
MAXmalware (ai score=65)
ArcabitTrojan.Adware.Cerbu.D12483
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Adware/Win.Adware-gen.R470980
McAfeeArtemis!4D75697E433A
VBA32Trojan.Ekstak
Cylanceunsafe
PandaTrj/CI.A
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.73555928.susgen
FortinetRiskware/Bodelph
AVGNSIS:Adware-AEK [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Adware.Cerbu.74883?

Adware.Cerbu.74883 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment