Malware

Cerbu.123513 (B) removal

Malware Removal

The Cerbu.123513 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.123513 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits possible ransomware file modification behavior
  • Likely virus infection of existing system binary

How to determine Cerbu.123513 (B)?


File Info:

name: EFF001F6B9AFE587EC2D.mlw
path: /opt/CAPEv2/storage/binaries/27aef323e46a6dbcefbe071d221d870a43c79bba737b750f936b11e336fecf6f
crc32: FBC5D2B2
md5: eff001f6b9afe587ec2d3faf519d09f2
sha1: 5d24cbb3b81cef1733c3e4e0f826676b794cb204
sha256: 27aef323e46a6dbcefbe071d221d870a43c79bba737b750f936b11e336fecf6f
sha512: 930d30ba6ec648d38dc1d0500211979cdbb5d17d10fa814ef8cc2aa6723b30659b2471cb331c28909b3af7536e165143f700f846818d01b226cbd70b9ac3c9a8
ssdeep: 196608:SecpIcg21czUyBlaTooXwEUiEi909YqFQ6styfOfa/H:Sell2aUYl81132f3tf6av
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E096233FB228B53ED4AA5B3205B3936059BBBA62651B8C2F03F0491CDF665601F3F651
sha3_384: 973f8181c1edab1b21f23b75d4a62bc3179762c04f36ed1de24240c2c98a6ff8991fe915783cb5656e98f16108156de9
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-03-14 17:59:41

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Disk Usage Analyzer Free 1.6.2 Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Disk Usage Analyzer Free 1.6.2
ProductVersion:
Translation: 0x0000 0x04b0

Cerbu.123513 (B) also known as:

MicroWorld-eScanGen:Variant.Cerbu.123513
FireEyeGen:Variant.Cerbu.123513
McAfeeArtemis!EFF001F6B9AF
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaAdWare:Win32/AdLoad.dde56569
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DKR21
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tmlc
BitDefenderGen:Variant.Cerbu.123513
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Adload.Aqqa
Ad-AwareGen:Variant.Cerbu.123513
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftGen:Variant.Cerbu.123513 (B)
GDataWin32.Backdoor.Bodelph.K2J1IJ
MAXmalware (ai score=81)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacGen:Variant.Cerbu.123513
MalwarebytesAdware.DownloadAssistant
APEXMalicious
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Cerbu.123513 (B)?

Cerbu.123513 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment