Malware

Cerbu.110680 removal tips

Malware Removal

The Cerbu.110680 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.110680 virus can do?

  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
cyark.cn

How to determine Cerbu.110680?


File Info:

crc32: 894E5389
md5: 4898ff53bf926a743d74520bb4cddec0
name: 4898FF53BF926A743D74520BB4CDDEC0.mlw
sha1: 624bbcd8d38d2ff053b5161fd6a979411053d13d
sha256: a8c25efe8d2e9528ae33d25e4f24d79b144f52b6fa0fdd19a2647abed6b0e3e3
sha512: c8ae10707690dc8521f1a051d83b6e5a9f99bdf9d9e71ffb67122e3efe1938981f5859a040b459e5c87f375cc8e180b164f1362a9483805b8416d674971338c3
ssdeep: 49152:Dcv4MTsUUC0pyaqP/uJ/rl8w+irA5KoMB4iVve+SYOPVVi:DcwkW9E/uJTN3r2KoMB4ixe+vwVi
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Cerbu.110680 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacGen:Variant.Cerbu.110680
CylanceUnsafe
BitDefenderGen:Variant.Cerbu.110680
Cybereasonmalicious.8d38d2
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusVirus.Win32.Agent.dvixmz
MicroWorld-eScanGen:Variant.Cerbu.110680
Ad-AwareGen:Variant.Cerbu.110680
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1119578
BitDefenderThetaGen:NN.ZexaF.34236.uoGfaK9EzadH
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.4898ff53bf926a74
EmsisoftGen:Variant.Cerbu.110680 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1119578
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Cerbu.D1B058
GDataGen:Variant.Cerbu.110680
Acronissuspicious
McAfeeFlyagent.d
MAXmalware (ai score=80)
VBA32BScope.Downloader.Snojan
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazq2mMDQJNqPqMx9U2EfI+mc)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.BELF!tr

How to remove Cerbu.110680?

Cerbu.110680 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment