Malware

Cerbu.125967 removal guide

Malware Removal

The Cerbu.125967 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.125967 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Cerbu.125967?


File Info:

name: EE1AEE20841850199528.mlw
path: /opt/CAPEv2/storage/binaries/b2adad30a983c35280baefaaa5175953548d64bd1ba7d28d2a4e6039041e0461
crc32: 2EB0F866
md5: ee1aee20841850199528dc452981254c
sha1: d7cb6cd933443ffc847b8b047239e1456f914003
sha256: b2adad30a983c35280baefaaa5175953548d64bd1ba7d28d2a4e6039041e0461
sha512: 01e7de7e16d6e86443239876c4f80473a2d6c93885f90cd4f218d11cec7f15e993a05bba947405e76f7f065c0b34128896fc6d8dde89ce3c01f9465bf265357f
ssdeep: 3072:GPckAQIY5VsV40x/Q/WcFNBLPLPU0VM4LLULLcoeuVo/LLL+LLLydL0Jm0kXLzZQ:c5VsV4Dw
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T16C1473868F5BCC10E5C500B05EE69FC9DE206B8A6E82FED28995D8F524341F7B6D7483
sha3_384: ba3a65da1b76a7a02f5eb4f03cbf2e3fc387331fd3592d1e85d4ae2f6b2c458ef84f6ed7a992e09e4f067008efcfe1dd
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-12-12 01:21:24

Version Info:

Translation: 0x0000 0x04b0
FileDescription: HwidSpoofer
FileVersion: 1.3.8.0
InternalName: HwidSpoofer.exe
LegalCopyright: Copyright © 2017-2021
OriginalFilename: HwidSpoofer.exe
ProductName: HwidSpoofer
ProductVersion: 1.3.8.0
Assembly Version: 0.0.0.0

Cerbu.125967 also known as:

LionicTrojan.MSIL.Crysan.m!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ee1aee2084185019
ALYacGen:Variant.Cerbu.125967
CylanceUnsafe
K7AntiVirusTrojan ( 0058970e1 )
AlibabaBackdoor:MSIL/Crysan.5732c744
K7GWTrojan ( 0058970e1 )
Cybereasonmalicious.933443
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ADGR
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
BitDefenderGen:Variant.Cerbu.125967
NANO-AntivirusTrojan.Win64.Crysan.jjavuk
MicroWorld-eScanGen:Variant.Cerbu.125967
AvastWin64:DropperX-gen [Drp]
TencentMsil.Backdoor.Crysan.Akys
Ad-AwareGen:Variant.Cerbu.125967
SophosMal/Generic-S
DrWebTrojan.Packed2.43254
TrendMicroTROJ_GEN.R002C0WLF21
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Cerbu.125967 (B)
IkarusTrojan.MSIL.Krypt
GDataGen:Variant.Cerbu.125967
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1145695
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Cerbu.D1EC0F
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Dropper/Win.Generic.C4645021
McAfeeArtemis!EE1AEE208418
MAXmalware (ai score=84)
VBA32Backdoor.MSIL.Crysan
TrendMicro-HouseCallTROJ_GEN.R002C0WLF21
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Kryptik.ADGR!tr
AVGWin64:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_70% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Cerbu.125967?

Cerbu.125967 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment