Malware

How to remove “Cerbu.146552”?

Malware Removal

The Cerbu.146552 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.146552 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • Likely virus infection of existing system binary

How to determine Cerbu.146552?


File Info:

name: 8B40C90CE34AC0B08D34.mlw
path: /opt/CAPEv2/storage/binaries/112940eec51cce924f652157d2787bdb10519cf169d8d71ea8b2d6ea35df4755
crc32: 2A813589
md5: 8b40c90ce34ac0b08d342bc90a6cf20b
sha1: fd519faa18d7df951fad63ccb8b7406c0abdaa35
sha256: 112940eec51cce924f652157d2787bdb10519cf169d8d71ea8b2d6ea35df4755
sha512: 40ea8d19742cd2652940be5be7a38b9d87349eb89e86008377b3dc7ca4f3040cd5c8f80cf4fc9b68fa301c5568a12011e4f19a4f0b9be50dc55ac0e65d5d8f68
ssdeep: 98304:YOQIUaXLUfcfg7WYbuFA8mYXya1TgwvNzxppPJ5tlDsaZjWEypzIFHJryJ9HS8t/:ygXLMcUNEnBFzbpHDnoE8MFH2SwCA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF6633B277C076B2C5621A763847E62C2313BD114906E60A705D7FB93AB73CBAA17743
sha3_384: 26f2a43dcf24f2efb3b1a99e19b0b5578bde50fdb2455d74e4a13ff11187f0a569a5d1cd08f272f6016d201f1ad9f0e9
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Novativh Solutions
FileDescription: Disk Cleaner
FileVersion: 6.0.0.4
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.146552 also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.146552
FireEyeGen:Variant.Cerbu.146552
McAfeeArtemis!8B40C90CE34A
CylanceUnsafe
VIPREGen:Variant.Cerbu.146552
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.abbab79f
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyTrojan.Win32.Ekstak.amjct
BitDefenderGen:Variant.Cerbu.146552
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-dropper.Agent.Ebgq
Ad-AwareGen:Variant.Cerbu.146552
EmsisoftGen:Variant.Cerbu.146552 (B)
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.IYPBZZ
JiangminTrojanDropper.Inokrypt.b
WebrootW32.Adware.Downloadassistant
ArcabitTrojan.Cerbu.D23C78
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
ALYacGen:Variant.Cerbu.146552
MAXmalware (ai score=81)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0DFU22
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Cerbu.146552?

Cerbu.146552 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment