Malware

Cerbu.126906 removal tips

Malware Removal

The Cerbu.126906 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.126906 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

How to determine Cerbu.126906?


File Info:

name: 4BF02B7AFAA01B398CA3.mlw
path: /opt/CAPEv2/storage/binaries/6e5b524af05d9644741753868f36bc864ec6a9bbb5b9aca8e6bb6a89eafab02e
crc32: A8DE8BAF
md5: 4bf02b7afaa01b398ca3d2bd11099c03
sha1: c5115fbf6155b5141746ed2798f51010900f715c
sha256: 6e5b524af05d9644741753868f36bc864ec6a9bbb5b9aca8e6bb6a89eafab02e
sha512: 2e1ab3cf21c4d94a28c2370144577ad09bc8ce4f01c4ed1977ab32971bcac3d4c4c948bab5b7dec63032f9cbe5d03678b8a2d496a4b073d7d2d1437beaa7f9d0
ssdeep: 98304:VppcDkbu0UCbQ7cDkwdiJ/Ifn9XRBMiJzKMSMr2r5S2i5/MhKitWG:Xp4kbbbZkmiJwhdhJSMyPiBWDn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A73633B62A8077F4F1BFE6FA0C7511204A617F2ADB1838B46A5E348DB6335A0D71D721
sha3_384: 731054d78a6f8d3992217c1d978b9d7b4ff7fa8ec1f30a312618dee47c5a46a31c253dd9278018de99f959493a35645f
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Data Doctor Pvt. Ltd.
FileDescription: DR (Professional) Recovery - Demo Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.126906 also known as:

MicroWorld-eScanGen:Variant.Cerbu.126906
FireEyeGen:Variant.Cerbu.126906
McAfeeArtemis!4BF02B7AFAA0
MalwarebytesAdware.DownloadAssistant
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.620c2891
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.akwai
BitDefenderGen:Variant.Cerbu.126906
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Cerbu.126906
EmsisoftGen:Variant.Cerbu.126906 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.QIHTHQ
JiangminTrojan.Ekstak.buyt
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Cerbu.D1EFBA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32Trojan.Ekstak
MAXmalware (ai score=83)
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H0DLP21
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Cerbu.126906?

Cerbu.126906 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment