Malware

Cerbu.105612 (file analysis)

Malware Removal

The Cerbu.105612 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.105612 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

api-flare.info

How to determine Cerbu.105612?


File Info:

crc32: 5B3366A9
md5: 56b5093e555768de58d329ba90afe188
name: 56B5093E555768DE58D329BA90AFE188.mlw
sha1: e0d29d7ec5150c58b10ee1fb96a5b9d26ec0e39c
sha256: 1a2c5a8888c80d11b093b8c81e8457b886c3371f2d6744529a7e91f3eaff2523
sha512: c900e7ae7aa209bbe804ab4e3ae47be518de41172b22a93cd5a1bdf3076b847d3e6301375122e2efbc0331d6a9c053b63b5159deb0d26822fe03c9d7f99a1021
ssdeep: 49152:7jVReBw0Y0fsvc4jimGT8twVOwATyvcO4zsAQ1v:SCl0frQimYpA+vcOJAm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2017 Piriform Ltd
InternalName: ccleaner
FileVersion: 5, 32, 00, 6129
CompanyName: Piriform Ltd
Comments: CCleaner
ProductName: CCleaner
ProductVersion: 5, 32, 00, 6129
FileDescription: CCleaner
OriginalFilename: ccleaner.exe
Translation: 0x0409 0x04b0

Cerbu.105612 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00537eb21 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3557
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Ekstak.A02
ALYacGen:Variant.Cerbu.105612
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 005334681 )
Cybereasonmalicious.e55576
CyrenW32/Trojan.CJN.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GHIS
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Cerbu.105612
NANO-AntivirusTrojan.Win32.InstallCube.fdnybx
MicroWorld-eScanGen:Variant.Cerbu.105612
TencentMalware.Win32.Gencirc.10c9c188
Ad-AwareGen:Variant.Cerbu.105612
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
McAfee-GW-EditionPacked-FGR!56B5093E5557
FireEyeGeneric.mg.56b5093e555768de
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
AviraTR/ICLoader.Gen8
MicrosoftSoftwareBundler:Win32/ICLoader
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataWin32.Adware.ICLoader.D
AhnLab-V3PUP/Win32.ICLoader.R229655
Acronissuspicious
McAfeePacked-FGR!56B5093E5557
MAXmalware (ai score=98)
VBA32Trojan.InstallCube
MalwarebytesAdware.ICLoader
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!3NoZI5QvlFo
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Packed.WIN32.Katusha.gen_216065
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Cerbu.105612?

Cerbu.105612 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment