Malware

Cerbu.115625 removal guide

Malware Removal

The Cerbu.115625 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.115625 virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Cerbu.115625?


File Info:

name: D5C6D80D004A64E905E2.mlw
path: /opt/CAPEv2/storage/binaries/37f2e4b200ce649c533419924bc1eb6d37859c4fddc702112ed361aef1241417
crc32: 4B3888D5
md5: d5c6d80d004a64e905e2cba21b25c194
sha1: ecff67bc1527188d8f97001bd48ba64442713756
sha256: 37f2e4b200ce649c533419924bc1eb6d37859c4fddc702112ed361aef1241417
sha512: 1c2c9c29f9cbb3a32d51b79c5869ab276db2f180201170d2608c86b3c927e316ddd8d1a2dff1ae34a4c4381c1fc85b7894512b4079cade1437fc69a35c78978d
ssdeep: 768:r2SvVXSZ1XjHkuttMzvbnZCMKl8zCoZp9Wt00+KHkN:r2y21XQuMnnZCVov9DwHG
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T154E2CF08FB848205C5BE4FB93E7B070026F1E34FA613D79D6DECA0E659A774405623EA
sha3_384: 3e43ee0d613951096629bc2d3ded0609cd4f08211a59f95d3a3649e30c0e22128e17e57c52420541c913fd560132080e
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2067-02-28 11:50:58

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Stub_64.exe
LegalCopyright:
OriginalFilename: Stub_64.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Cerbu.115625 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.115625
CAT-QuickHealTrojan.MsilFC.S19426763
ALYacGen:Variant.Cerbu.115625
CylanceUnsafe
Cybereasonmalicious.c15271
ESET-NOD32a variant of MSIL/Spy.Agent.DDO
ClamAVWin.Packed.Tasker-9878136-0
KasperskyHEUR:Backdoor.MSIL.Horus.gen
BitDefenderGen:Variant.Cerbu.115625
Ad-AwareGen:Variant.Cerbu.115625
F-SecureHeuristic.HEUR/AGEN.1143541
McAfee-GW-EditionBehavesLike.Win64.VirRansom.nc
SentinelOneStatic AI – Suspicious PE
FireEyeGeneric.mg.d5c6d80d004a64e9
EmsisoftGen:Variant.Cerbu.115625 (B)
IkarusTrojan.MSIL.Bladabindi
AviraHEUR/AGEN.1143541
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Cerbu.D1C3A9
GDataMSIL.Trojan-Spy.Agent.BCG
CynetMalicious (score: 100)
AhnLab-V3Malware/Win64.RL_Generic.C4338149
McAfeeGenericRXOG-OW!D5C6D80D004A
MalwarebytesMalware.AI.4130118907
APEXMalicious
MAXmalware (ai score=89)
AVGWin64:DropperX-gen [Drp]
AvastWin64:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Cerbu.115625?

Cerbu.115625 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment