Malware

How to remove “Cerbu.128543 (B)”?

Malware Removal

The Cerbu.128543 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.128543 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

How to determine Cerbu.128543 (B)?


File Info:

name: 53260729F510B6E8792F.mlw
path: /opt/CAPEv2/storage/binaries/cf8dc506500b6ab9194e3c3551641754b0a84ef10a1c4b9896e633da18f3a487
crc32: A82307D7
md5: 53260729f510b6e8792fa268c78ebe82
sha1: 9a34c248f5e1977919f86557b1b85e938032530c
sha256: cf8dc506500b6ab9194e3c3551641754b0a84ef10a1c4b9896e633da18f3a487
sha512: 5636b69c2def592ed6deda98fe55e8ffaf695abf8261f543a868e2302290451d42f22e14ede360cdd912effe4ee9ab6b736e398a2aeaae615e4bc1750190a782
ssdeep: 196608:vdtzJ7VvaqvfGX9OLKflGzuDkDyWTCilVRqj6uWrKkGsDWCUpEgr:FhJVfGX9OlBCiTRqGuWrXvUugr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A5633B254BF053AF6B94F30D4F6491DE3BAFD800C549ADA24DE6F18A6A92D1F010673
sha3_384: 8d0e87d09f2cf98af820b5752929f58df0780d8d045e4d1d117ed40b69f82673d89692bbe110badcd097cdf93d947f01
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Afaiko Software
FileDescription: CD Catalog Professional Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.128543 (B) also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.128543
FireEyeGen:Variant.Cerbu.128543
McAfeeArtemis!53260729F510
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.106c20d9
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.DZH.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002C0WAM22
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.alklo
BitDefenderGen:Variant.Cerbu.128543
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Ekstak.Ssqo
Ad-AwareGen:Variant.Cerbu.128543
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WAM22
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftGen:Variant.Cerbu.128543 (B)
GDataWin32.Backdoor.Bodelph.GK7JHQ
JiangminTrojan.Ekstak.bvbx
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VBA32Trojan.Ekstak
ALYacGen:Variant.Cerbu.128543
MAXmalware (ai score=82)
MalwarebytesAdware.DownloadAssistant
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove Cerbu.128543 (B)?

Cerbu.128543 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment