Malware

Cerbu.107632 removal instruction

Malware Removal

The Cerbu.107632 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.107632 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Looks up the external IP address

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipinfo.io

How to determine Cerbu.107632?


File Info:

crc32: B59BA14E
md5: a57a377468248cf45c918a58563291e7
name: A57A377468248CF45C918A58563291E7.mlw
sha1: c99d3a790cc800e0606b4a80dffb3843b9079e38
sha256: 51c250f186207f9cdaea4aae96f63f99a33fe925518de0d4f1d7a1657ff073e9
sha512: 68b0ff91a030c7fbb7c3132e46df097e24d037abfc075d69aa0087103e4b579b7d215aa19ea118a4e08b8b55e3b84917167b21dc2d231dec3265ae2ca999cee4
ssdeep: 3072:nAGPE9FD9D8PrnrUd9Iq0Rh0PgPYtbKZFJ9W4Aaq81r9jFaWZPPeb:n/EtoDnrUd9Iq0xYtOrJ9WmqKjnZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyrightxa9 2012-2015
Assembly Version: 7.0.6101.18044
InternalName: inetinfo.exe
FileVersion: 7.0.6101.18044
Comments: Internet Information Service
ProductVersion: 7.0.6101.18044
FileDescription: InetInfo
OriginalFilename: inetinfo.exe

Cerbu.107632 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Cerbu.107632
CylanceUnsafe
SangforTrojan.Win32.Generic.8
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.468248
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.OxyPumper.Y
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Cerbu.107632
NANO-AntivirusRiskware.Win32.OxyPumper.esnxcy
MicroWorld-eScanGen:Variant.Cerbu.107632
TencentMsil.Adware.Oxypumper.Lmas
Ad-AwareGen:Variant.Cerbu.107632
SophosGeneric PUA MJ (PUA)
ComodoApplicUnwnt@#1fg94smhqqggp
BitDefenderThetaGen:NN.ZemsilF.34294.nq0@a41IRH
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.a57a377468248cf4
EmsisoftGen:Variant.Cerbu.107632 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.21B959A
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Cerbu.D1A470
SUPERAntiSpywareAdware.OxyPumper/Variant
GDataGen:Variant.Cerbu.107632
McAfeeArtemis!A57A37746824
MAXmalware (ai score=99)
MalwarebytesMalware.AI.3017778880
PandaTrj/GdSda.A
YandexPUA.OxyPumper!vGa/ook/G7g
IkarusAdWare.MSIL.OxyPumper
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/PUP_XCB
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Cerbu.107632?

Cerbu.107632 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment