Malware

Cerbu.117894 removal

Malware Removal

The Cerbu.117894 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.117894 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
xgod23.ddns.net

How to determine Cerbu.117894?


File Info:

crc32: BA04DB38
md5: 964503689fbb3e61e07ac041d3bdd8b0
name: 964503689FBB3E61E07AC041D3BDD8B0.mlw
sha1: d8545d74b1f77f52fac3082a857c54443e956788
sha256: d2875bcc2ae14eb5fe6863c4d7e6769f34ba249232ad46001f5d9e28ecfe6249
sha512: fefdf82fc42630bbccd2f3a4d98fea8f5154976d2822ebbbbc11cee78a1c761e83d0881d206d9777bbdc754d6fe2f10b86d89ea9465c5bb91b33e8fa08627dca
ssdeep: 384:+84ODG7i0xeC9E2xzeyEuzpTXfdUFIqzLcY/D:KOyGQZ68dY/D
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Client.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Client.exe

Cerbu.117894 also known as:

K7AntiVirusTrojan ( 005202e81 )
LionicTrojan.MSIL.Agent.m!c
Elasticmalicious (high confidence)
DrWebBackDoor.BladabindiNET.10
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MsilFC.S16693352
ALYacGen:Variant.Cerbu.117894
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Bladabindi.cfb72a77
K7GWTrojan ( 005202e81 )
Cybereasonmalicious.89fbb3
CyrenW32/MSIL_Troj.TG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.IU
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.njRAT-7445143-0
KasperskyHEUR:Backdoor.MSIL.Agent.gen
BitDefenderGen:Variant.Cerbu.117894
MicroWorld-eScanGen:Variant.Cerbu.117894
TencentMsil.Backdoor.Agent.Hsif
Ad-AwareGen:Variant.Cerbu.117894
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34236.bm0@auPZEDe
TrendMicroTROJ_GEN.R002C0DJV21
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.964503689fbb3e61
EmsisoftGen:Variant.Cerbu.117894 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen7
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Variant.Cerbu.117894
AhnLab-V3Trojan/Win32.SpyGate.R292993
McAfeeTrojan-FSCF!964503689FBB
MAXmalware (ai score=85)
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DJV21
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladibindi.IU!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Cerbu.117894?

Cerbu.117894 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment