Malware

Cerbu.147104 (file analysis)

Malware Removal

The Cerbu.147104 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.147104 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Likely virus infection of existing system binary

How to determine Cerbu.147104?


File Info:

name: AAE2EF22D5107ABEB4F5.mlw
path: /opt/CAPEv2/storage/binaries/36c7a70ebafecc94a8e33f1f4c5a5578c3c81dc552a69e6afd767f2e31fb9c28
crc32: ACFA7172
md5: aae2ef22d5107abeb4f51cfe5fcc6ff0
sha1: 10caf08ef4de07368e95ffad9a70dce8b93a34b6
sha256: 36c7a70ebafecc94a8e33f1f4c5a5578c3c81dc552a69e6afd767f2e31fb9c28
sha512: 9ae2a9f89d300f0b8d158d25f02c85b14c676c89d67d20bea137af7d52e59c6439b49abf23bd6cc07cb68cdcde8afc0f47890a16ee97a508e12cc6d8b7a16e73
ssdeep: 196608:yvOHeNk7x6if6u06ZcIZ5PpTIHsP8jmMjMEl7KXIEcCA:yWHV7/N00PpTIHI8vj9l6IE7A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F96633F0799073B6D6716737E64713280533BC9A0407E60A6284BF2637773E2A72796E
sha3_384: 1c15ddb4120c47e86c40e027908b2a48e11480a87b39ed3cf7e8663806ab85782eac701470a80322a03b6a905abf353e
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Novativj Solutions
FileDescription: Disk Cleaner
FileVersion: 6.0.0.6
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.147104 also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.147104
FireEyeGen:Variant.Cerbu.147104
McAfeeArtemis!AAE2EF22D510
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.9d47d07c
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.CG.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DG222
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.amjgl
BitDefenderGen:Variant.Cerbu.147104
NANO-AntivirusTrojan.Win32.Ekstak.jpymsz
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-dropper.Agent.Lqoo
Ad-AwareGen:Variant.Cerbu.147104
EmsisoftGen:Variant.Cerbu.147104 (B)
VIPREGen:Variant.Cerbu.147104
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojanDropper.Inokrypt.b
AviraTR/Drop.Agent.ehqjq
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Cerbu.147104
CynetMalicious (score: 99)
AhnLab-V3Adware/Win.Adware-gen.R503210
ALYacGen:Variant.Cerbu.147104
MAXmalware (ai score=85)
MalwarebytesAdware.DownloadAssistant
AVGWin32:Adware-gen [Adw]

How to remove Cerbu.147104?

Cerbu.147104 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment