Malware

Should I remove “Cerbu.107107”?

Malware Removal

The Cerbu.107107 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.107107 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Cerbu.107107?


File Info:

name: 226410AB9E2173638954.mlw
path: /opt/CAPEv2/storage/binaries/6f4f0fe5960158e6ba8cfe710e6afb9929d4dbdeba2c4d3eed706c50aa76f7e9
crc32: 56C121CC
md5: 226410ab9e2173638954dfaccebe20e3
sha1: 232785c5e0d24e03db776ae456134cde7729d631
sha256: 6f4f0fe5960158e6ba8cfe710e6afb9929d4dbdeba2c4d3eed706c50aa76f7e9
sha512: 310de3b14525b0886f007e6fcf77b491c9c25ccfcfa51a28eaa83753a55a44c39f26fe479c0d2cbee24a592664e36eae8c0f108a5cc843262bfd4165e8b47ce3
ssdeep: 3072:GGFQVjHYVzekWzWfMkbT831XoBjD+gpcr6j4atmL5Od9hJjsC6CRzJ1:r+NYUk1T83Yjzpcr68bQjsu
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15CF317AA32C58F02D3882DB8C0E38A2513E699C76776E38D3E5009DA1D517E4DE4F3D9
sha3_384: 705cd434882ed5cfca35cc41a0d0b05f538ff94634b796c60f068e56d4f4fbb7ea2f3d923ba1900fdc5d6e1d948ac188
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-16 18:16:21

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: output.exe
LegalCopyright:
OriginalFilename: output.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Cerbu.107107 also known as:

LionicTrojan.MSIL.Disco.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.107107
FireEyeGeneric.mg.226410ab9e217363
ALYacGen:Variant.Cerbu.107107
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2660767
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:MSIL/Disco.137120ce
K7GWSpyware ( 0057f64b1 )
K7AntiVirusSpyware ( 0057f64b1 )
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DKS
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Disco.gen
BitDefenderGen:Variant.Cerbu.107107
AvastWin32:SpywareX-gen [Trj]
TencentMsil.Trojan-qqpass.Qqrob.Hoye
Ad-AwareGen:Variant.Cerbu.107107
EmsisoftGen:Variant.Cerbu.107107 (B)
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S
IkarusTrojan.MSIL.TrojanClicker
GDataGen:Variant.Cerbu.107107
AviraHEUR/AGEN.1235904
Antiy-AVLTrojan/Generic.ASMalwS.3520F1B
GridinsoftRansom.Win32.Bladabindi.sa
ArcabitTrojan.Cerbu.D1A263
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4551389
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002H0CB422
RisingTrojan.Generic/MSIL@AI.90 (RDM.MSIL:KP2yLyNf6rjhnX0CwQgDYw)
YandexTrojanSpy.Agent!z7w3umC+yl4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DKS!tr.spy
BitDefenderThetaGen:NN.ZemsilF.34212.km0@aippMNc
AVGWin32:SpywareX-gen [Trj]
Cybereasonmalicious.5e0d24
PandaTrj/GdSda.A

How to remove Cerbu.107107?

Cerbu.107107 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment