Malware

Cerbu.128775 (B) removal

Malware Removal

The Cerbu.128775 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.128775 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary

How to determine Cerbu.128775 (B)?


File Info:

name: D2E894CEA01CD16A2D1B.mlw
path: /opt/CAPEv2/storage/binaries/47bf44bb3f49741226db53e07e96845548c31e5117b0d44cbfa910e01a480bfa
crc32: 8EB001DB
md5: d2e894cea01cd16a2d1b618a030c536e
sha1: 1b163aaf778656482b0a3dd2c37fa82442a8e879
sha256: 47bf44bb3f49741226db53e07e96845548c31e5117b0d44cbfa910e01a480bfa
sha512: 2550bb6c4f7bf32b426cbf41515623a15261d08241229e8288b2841c126b87da39d3677faedc24e5bf99c3e627e895ff02833bab60bf098ef4935a3166056c5a
ssdeep: 98304:449Au9TbWAH7tdeOeiynhbkMAMsgmTSqw7yMhQQXRdY11uDFmgLC/wedU+V46bF1:F9x/n7De5kMvmTchQgdm1uggLCoedU+n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1784633C3E6D861FBCCB4687192638DB102E35D3AE5183DA250EEB63E5B36350163652F
sha3_384: b8e7014cc7b6605ff376d90567854b5311dfb22dd54ce040e274f77e94eda656e7cdfc1d4fc3b5e9302afec137eb6c9b
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: iMobie Inc.
FileDescription: PhoneRescue Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.128775 (B) also known as:

LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.128775
FireEyeGen:Variant.Cerbu.128775
ALYacGen:Variant.Cerbu.128775
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R03FC0GAS22
KasperskyTrojan.Win32.Ekstak.almin
BitDefenderGen:Variant.Cerbu.128775
AvastWin32:Trojan-gen
TencentWin32.Trojan.Ekstak.Wsjw
Ad-AwareGen:Variant.Cerbu.128775
EmsisoftGen:Variant.Cerbu.128775 (B)
ComodoMalware@#1tpj76t6z0f6r
TrendMicroTROJ_GEN.R03FC0GAS22
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
GDataGen:Variant.Cerbu.128775
JiangminTrojan.Ekstak.bveb
AviraHEUR/AGEN.1219006
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Cerbu.D1F707
ZoneAlarmTrojan.Win32.Ekstak.almin
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!D2E894CEA01C
MAXmalware (ai score=87)
VBA32Trojan.Ekstak
YandexTrojan.DR.Agent!mWXHdberMC4
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
MaxSecureTrojan.Malware.73555928.susgen

How to remove Cerbu.128775 (B)?

Cerbu.128775 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment