Malware

Cerbu.137254 information

Malware Removal

The Cerbu.137254 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.137254 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing

How to determine Cerbu.137254?


File Info:

name: 2F9B6C73FCC783089A43.mlw
path: /opt/CAPEv2/storage/binaries/0c75bef5ce8f351118136cdc39570f636ade13237d9f53a28f85558eebdf5c27
crc32: 08D239D4
md5: 2f9b6c73fcc783089a43296abd8bcb97
sha1: ee8e328d50e5beea668101356067c9e2ea86a6af
sha256: 0c75bef5ce8f351118136cdc39570f636ade13237d9f53a28f85558eebdf5c27
sha512: e75ccfc721479c8122f71e86ccde62a574e37383744011c1fefb81d3a9c6cb2415988674f1b70685ea11107b5b977acb7007c7615e9ae9603a6d57a172e0e507
ssdeep: 98304:DyopOT3INZa7lIx/OlP/JQRE6uOoeaJDyHl10OyLNq9F2WRwFBLotPkb69ZA27nk:OnINZa7lIOlP/JCuOoVmT0swF5otPK6W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B03633FBA99C54F5F260E875A932EE8C5F57BCC0AA3CC81235B97DC4093C761911A983
sha3_384: 4735456c056726176f9e7d62b56fe21b6a1d880274b73d073e72293e235384b7d5b581132608a07630f44a755c0fe712
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: http://ionsoftware.com/
FileDescription: Browser Cleaner Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.137254 also known as:

LionicTrojan.Win32.Cerbu.4!c
MicroWorld-eScanGen:Variant.Cerbu.137254
FireEyeGen:Variant.Cerbu.137254
ALYacGen:Variant.Cerbu.137254
CylanceUnsafe
SangforTrojan.Win32.Agent.Vl7c
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Generic.b63242d7
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.EFZ.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0CHN22
KasperskyTrojan.Win32.Ekstak.amqfp
BitDefenderGen:Variant.Cerbu.137254
CynetMalicious (score: 99)
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Cerbu.137254
VIPREGen:Variant.Cerbu.137254
EmsisoftGen:Variant.Cerbu.137254 (B)
GDataWin32.Backdoor.Bodelph.FWSNMS
JiangminTrojan.Ekstak.bvup
AviraHEUR/AGEN.1248410
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!2F9B6C73FCC7
MAXmalware (ai score=80)
MalwarebytesAdware.DownloadAssistant
IkarusTrojan-Dropper.Win32.Agent
AVGWin32:Adware-gen [Adw]

How to remove Cerbu.137254?

Cerbu.137254 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment