Malware

Application.Cerbu.28990 removal

Malware Removal

The Application.Cerbu.28990 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Cerbu.28990 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

How to determine Application.Cerbu.28990?


File Info:

name: B2C89BACA3D828EADEC0.mlw
path: /opt/CAPEv2/storage/binaries/b92eb273ead20455039061ea8a2d6aa050d23ea9a24be6a343048f77d3a31efc
crc32: 71FC36F5
md5: b2c89baca3d828eadec0c332422de81b
sha1: 9473fd0b95b4ae691aaef14774cfc0eb79687a73
sha256: b92eb273ead20455039061ea8a2d6aa050d23ea9a24be6a343048f77d3a31efc
sha512: 71aa7fde2f122a1a4ab7673bbb3a4c309f34804dc40ab418812a026ee06df10e9fd094484eaee73d42adaa52af585cc6ff0c726f614d0f5030074011f0cc26f7
ssdeep: 768:QBWPMPpgvAJ1I9p/++ggnAb14gL9wYhlTG73j03YG/MG27DmOMm:QZuAW/+oAR7e3jfGBO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E4437FDBFFD241B1C69502F0893E394BDFA25205433086E7D784B9196E621EBC67C3A5
sha3_384: 83774c0100728378df095587aaa91a6c43651c173aaf35f2b16f14416d5c9108409b3a1e6e962ab52f1bb2ee0cd0e58f
ep_bytes: 68c800000068000000006818c34000e8
timestamp: 2011-03-25 13:17:42

Version Info:

0: [No Data]

Application.Cerbu.28990 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lE5I
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Cerbu.28990
FireEyeGeneric.mg.b2c89baca3d828ea
ALYacGen:Variant.Application.Cerbu.28990
CylanceUnsafe
ZillyaTrojan.Fynloski.Win32.7233
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanDropper:Win32/Cerbu.f9f4f4dd
K7GWTrojan ( 0052964f1 )
K7AntiVirusTrojan ( 0052964f1 )
CyrenW32/Cerbu.P.gen!Eldorado
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
ClamAVWin.Malware.Bavs-6804154-0
BitDefenderGen:Variant.Application.Cerbu.28990
NANO-AntivirusTrojan.Win32.TrjGen.tbdhj
AvastFileRepMalware
Ad-AwareGen:Variant.Application.Cerbu.28990
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.CoinMiner.IEGT@57p1bc
McAfee-GW-EditionBehavesLike.Win32.PUPXAX.qm
EmsisoftGen:Variant.Application.Cerbu.28990 (B)
IkarusPacker.Win32.Krap
GDataGen:Variant.Application.Cerbu.28990
AviraTR/Dropper.Gen
MAXmalware (ai score=79)
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/Ymacco.ABB9
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXAA-AA!B2C89BACA3D8
VBA32Trojan.Hosts
APEXMalicious
RisingTrojan.Generic@ML.100 (RDMK:R19m4+keKWtVym9OaYdulQ)
YandexTrojan.GenAsa!Zi7ep0Wcoso
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cerbu.P!tr
AVGFileRepMalware
Cybereasonmalicious.ca3d82

How to remove Application.Cerbu.28990?

Application.Cerbu.28990 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment