Malware

Cerbu.109524 removal tips

Malware Removal

The Cerbu.109524 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.109524 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Cerbu.109524?


File Info:

name: F2378A9DD64C2277C09B.mlw
path: /opt/CAPEv2/storage/binaries/0408dd2a991c5c9a30c0f5ab8d51cae88a1d908748fc539fd102d1a9bbf840a9
crc32: 22E46923
md5: f2378a9dd64c2277c09b2875719166ca
sha1: 8dd42fc67091b42b987a0ba25a9bcf0ebf78cd16
sha256: 0408dd2a991c5c9a30c0f5ab8d51cae88a1d908748fc539fd102d1a9bbf840a9
sha512: 74220429eba85e52677e1a02fa0f48ff865ecc568f904b81cadf1d71d5bba05c5522a31ed1b9beb7a7aaf96f522ae54fe4826efb9ae7328ba2ca8a3f933e6f63
ssdeep: 1536:352atTZSHYH1iC8ghLpfia/AUTSPEBC7xbYBBB9sqrkhGKsWrd7B9dl0SMGv:4adsMNppfR/PT+Es7xbcsqkEGVaSM
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T187C37D5773A970F9D4778239C8650906E77278360636CBAF039856662F373A19E3EF20
sha3_384: 244aa58559dd338051df74c7e9980d772774a06af02ec8018d972a0245807328aeca5f13d091aa15cd83a4bbf3ca3822
ep_bytes: 4883ec28e85b0200004883c428e972fe
timestamp: 2021-08-01 15:22:56

Version Info:

0: [No Data]

Cerbu.109524 also known as:

LionicTrojan.Win32.Cerbu.4!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Shelma-9864690-0
FireEyeGen:Variant.Cerbu.109524
McAfeeRDN/Generic.grp
CylanceUnsafe
K7AntiVirusTrojan ( 005819301 )
AlibabaTrojan:Win64/Kryptik.291951fd
K7GWTrojan ( 005819301 )
CyrenW64/Trojan.OKKC-4241
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Kryptik.COR
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Cerbu.109524
MicroWorld-eScanGen:Variant.Cerbu.109524
AvastWin64:CrypterX-gen [Trj]
Ad-AwareGen:Variant.Cerbu.109524
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PHA21
McAfee-GW-EditionRDN/Generic.grp
EmsisoftGen:Variant.Cerbu.109524 (B)
IkarusTrojan.Win64.Agent
GDataGen:Variant.Cerbu.109524
JiangminTrojan.Cometer.bfl
AviraTR/AD.MeterpreterSC.hbynl
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R436567
ALYacGen:Variant.Cerbu.109524
MAXmalware (ai score=87)
TrendMicro-HouseCallTROJ_GEN.R002C0PHA21
MaxSecureTrojan.Malware.120039742.susgen
FortinetW32/PossibleThreat
AVGWin64:CrypterX-gen [Trj]

How to remove Cerbu.109524?

Cerbu.109524 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment