Malware

Cerbu.128064 removal

Malware Removal

The Cerbu.128064 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.128064 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

How to determine Cerbu.128064?


File Info:

name: 344936BBC432AEDE40DF.mlw
path: /opt/CAPEv2/storage/binaries/12aab9c4d77d8ad0c3ef3a8eb40196b0c424daa6813e0ad66ff09d343d9988b2
crc32: 6857373A
md5: 344936bbc432aede40dfd5c4057115c7
sha1: ac7c345ad9a2decc2f068f51debe81841219e272
sha256: 12aab9c4d77d8ad0c3ef3a8eb40196b0c424daa6813e0ad66ff09d343d9988b2
sha512: 51cbae3efdfd8c5e90a69a4883e6d99950259339d9d825c42075660580dbc98c343efdf50716af6da97f0fec16d821b621878440f030a012ef0da68dabc0476d
ssdeep: 196608:sv+pIrvb9o++gfgBksHLvai3xgcPYBMLEH2as:3ieEfqpH13xgugMLS2as
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142663370A6C153F5D2E56AF9883153C41E023E3D26342217758A6F9EFDDBB63860F628
sha3_384: 4f27ffc742b0c67a70c9c042284eea5c27f6f3ac9d67e560254d6419e5011fea22ee7e212df2d49ea57c934019adfea6
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Akajkw Software
FileDescription: CK Catalog Professional Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.128064 also known as:

LionicTrojan.Win32.Cerbu.4!c
MicroWorld-eScanGen:Variant.Cerbu.128064
FireEyeGen:Variant.Cerbu.128064
McAfeeArtemis!344936BBC432
MalwarebytesAdware.DownloadAssistant
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.be372f5a
K7GWTrojan ( 005722fe1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Agent.DZH.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R067C0WAN22
Paloaltogeneric.ml
ClamAVWin.File.Conduit-9936286-0
KasperskyTrojan.Win32.Ekstak.alkwk
BitDefenderGen:Variant.Cerbu.128064
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Ekstak.Lhwz
EmsisoftGen:Variant.Cerbu.128064 (B)
TrendMicroTROJ_GEN.R067C0WAN22
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SophosMal/Generic-S
JiangminTrojan.Ekstak.bvcq
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Sabsik!ml
GDataWin32.Backdoor.Bodelph.PGBE1D
CynetMalicious (score: 100)
ALYacGen:Variant.Cerbu.128064
CylanceUnsafe
YandexTrojan.Ekstak!IBb/DSMZ6R4
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove Cerbu.128064?

Cerbu.128064 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment