Malware

Cerbu.146077 removal guide

Malware Removal

The Cerbu.146077 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.146077 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Likely virus infection of existing system binary

How to determine Cerbu.146077?


File Info:

name: F418BD6A9498C6A78200.mlw
path: /opt/CAPEv2/storage/binaries/44bf070b6dfcdff21bfcd3cb1e21a4e366786722aea468e12135c9f5e657e975
crc32: D5ADFF9E
md5: f418bd6a9498c6a78200c7b2ca331538
sha1: 954e1a330ba84d6252cead88b51788c41b24454f
sha256: 44bf070b6dfcdff21bfcd3cb1e21a4e366786722aea468e12135c9f5e657e975
sha512: 2a03a12bc75be665bd0e3bee95cbfc675b9b685b1e2aca67766ee8386f5b72d3104f7597b71bfe1744b73c514eeef25c9c68dc090956ba8173c3f4401b4c576b
ssdeep: 196608:WoZhEmsuwiJYNEbT6Y4nBvVtG7pS/vCYukVfX4vZLEu:zhlvJQEbGLPLvCYPX4vZj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC66330FBFD368B1E8CE0B7B6E84C6C167373C71187A4519318C33AE5D3A4AAE519259
sha3_384: d5ad56778aa1a2d0323e8188f88e780ac9a402890cab2c1aeff8bfa27d2d5a0bf3d4d6faf37670695f1c49c902c8d3eb
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Bisvio, LLC
FileDescription: Bisvio Disk Cleaner Free
FileVersion: 1.2.0.18
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.146077 also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.146077
FireEyeGen:Variant.Cerbu.146077
ALYacGen:Variant.Cerbu.146077
CylanceUnsafe
VIPREGen:Variant.Cerbu.146077
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.8357d3c3
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DFP22
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.amilp
BitDefenderGen:Variant.Cerbu.146077
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-dropper.Agent.Eacu
Ad-AwareGen:Variant.Cerbu.146077
EmsisoftGen:Variant.Cerbu.146077 (B)
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan-Dropper.Win32.Agent
GDataGen:Variant.Cerbu.146077
JiangminTrojan.Ekstak.bysa
ArcabitTrojan.Cerbu.D23A9D
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Generic.R501515
McAfeeArtemis!F418BD6A9498
MalwarebytesAdware.DownloadAssistant
MAXmalware (ai score=82)
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:Adware-gen [Adw]

How to remove Cerbu.146077?

Cerbu.146077 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment