Malware

Cerbu.113587 removal

Malware Removal

The Cerbu.113587 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.113587 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Cerbu.113587?


File Info:

name: C15D2216F66915A7981B.mlw
path: /opt/CAPEv2/storage/binaries/d67650bfae580d381c902e8a6916c1a665d836985f9cdbbfb4f565414918ff86
crc32: 340387E6
md5: c15d2216f66915a7981b9f4115390d16
sha1: af038b693ff636eefa14750ff2bda7ff7eb2c53b
sha256: d67650bfae580d381c902e8a6916c1a665d836985f9cdbbfb4f565414918ff86
sha512: 10942ddc117c73e74243455d638406984d46490937b34d4158823e788dc13bb18c0725a40d81fda7ba98923f13f77b942c620f378e44c39fa0fe641580277b05
ssdeep: 1536:y/Nus4phrF6RY5BDgWLXqnm4HVxjInkWr4TMMYlC99Sep9WS:yw6RYDgWLMm4snkWrgXY2SepYS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145B37D0876808037C15B4739D8B39A459B7AB80557F2A38F3EA952AF5F333D09B3A355
sha3_384: ef342115e9643bf4d1add1773893d5b5d53a40d89a3cff66c081d68bd34bce5603d7e157be4f65575db7f372d9e5f699
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-08-27 05:44:54

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Unpack me
FileVersion: 1.0.0.0
InternalName: Unpack me.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Unpack me.exe
ProductName: Unpack me
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Cerbu.113587 also known as:

LionicTrojan.Win32.Cerbu.4!c
MicroWorld-eScanGen:Variant.Cerbu.113587
McAfeeGenericRXRC-VV!C15D2216F669
CylanceUnsafe
Cybereasonmalicious.6f6691
CyrenW32/Zbot.AQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Cerbu.113587
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Cerbu.113587
EmsisoftGen:Variant.Cerbu.113587 (B)
DrWebTrojan.PWS.Stealer.29975
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.c15d2216f66915a7
SophosGeneric ML PUA (PUA)
IkarusTrojan.MSIL.PSW
GDataGen:Variant.Cerbu.113587
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1141703
MAXmalware (ai score=84)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4740800
BitDefenderThetaGen:NN.ZemsilF.34084.hm0@aKBdarn
ALYacGen:Variant.Cerbu.113587
VBA32Worm.Bundpil
TrendMicro-HouseCallTROJ_GEN.R002H09L721
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Cerbu.113587?

Cerbu.113587 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment