Malware

Should I remove “Cerbu.128892”?

Malware Removal

The Cerbu.128892 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.128892 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Cerbu.128892?


File Info:

name: 84EB83A032F7EC814F96.mlw
path: /opt/CAPEv2/storage/binaries/48a71e76fe48f1b9ad8dcc22a480419ef89f46567fab349fb9b55552ab3bff20
crc32: 6A7612BD
md5: 84eb83a032f7ec814f96000120b31950
sha1: 99544d1d1f260994f43003d51b5257583e46029c
sha256: 48a71e76fe48f1b9ad8dcc22a480419ef89f46567fab349fb9b55552ab3bff20
sha512: 012b404f8fa400913818065ebd8f2a51a701e4ab3b2638aaa78636a7de2c407b9e5d540dcd401fa5b7ba396a082a8577fe6ae27268966f1855afbfb73308d1f0
ssdeep: 12288:fsZjg4HAjuakTOfDlEU4hymOcB+pwPprnVmLmDsC+FU+ZOSzt9tzZ:EZrwu/OfDlEUaLOsDFncLmKDZOSzXFZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BBE46E32A6504033E7E10573AD19D6307E7CA3286B21C9A7D3D4ED1D6EA84D2ABF7217
sha3_384: 3f7b68ce1fbd44c58dcb0fff5fea0917813606b2f5ddf79e4b1dc3dea766363704240226734b79057c1c1e952c4c38b1
ep_bytes: 04d140008bc75f5b5ec3535657e89413
timestamp: 2016-12-13 17:04:22

Version Info:

0: [No Data]

Cerbu.128892 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.84eb83a032f7ec81
ALYacGen:Variant.Cerbu.128892
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
CyrenW32/Shohdi.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H09AS22
BitDefenderGen:Variant.Cerbu.128892
MicroWorld-eScanGen:Variant.Cerbu.128892
AvastFileRepMalware
Ad-AwareGen:Variant.Cerbu.128892
EmsisoftGen:Variant.Cerbu.128892 (B)
McAfee-GW-EditionRDN/Generic.grp
SophosGeneric ML PUA (PUA)
IkarusVirus.Win32.HLLP
GDataGen:Variant.Cerbu.128892
ArcabitTrojan.Cerbu.D1F77C
MicrosoftTrojan:Script/Phonzy.C!ml
McAfeeRDN/Generic.grp
MAXmalware (ai score=88)
APEXMalicious
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Shohdi.D!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Cerbu.128892?

Cerbu.128892 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment