Malware

Cerbu.148497 (B) removal instruction

Malware Removal

The Cerbu.148497 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.148497 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Likely virus infection of existing system binary
  • Deletes executed files from disk

How to determine Cerbu.148497 (B)?


File Info:

name: C4181BCCB5B28C90AA12.mlw
path: /opt/CAPEv2/storage/binaries/20345109fb6a5fb59bce9173406f8dd6b96ecf799efa9afea2c8864c68a7b659
crc32: BE742F77
md5: c4181bccb5b28c90aa121190ec6ca4fa
sha1: 6f525b0f73443b04970910bb58bf88107c7196a0
sha256: 20345109fb6a5fb59bce9173406f8dd6b96ecf799efa9afea2c8864c68a7b659
sha512: 9c6b5d5f69f4acbe2727506389aa3a34e40b84c217a97f99dae30d04ce4fbb2d5ea086995ad3412bc3d413e822efb20937ce8efeb8b77d162ca22a444090582a
ssdeep: 196608:clatVbk0067GQP8wk7xAANe25P02otIfYA/+qdAwLKPo:clIvnCQrqe25PjoCB+qHLv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173763367CB99CE3BF0D5F97444BC8171A99EBB0938099E34C1787EA2D2AF4081B57187
sha3_384: 59a786b62bcb43ffe6ff89ecca3ba7577527c2f3e83bcf5761db009addf92497099a959bb99f7e8310c5e70efb4afe87
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: LionMaz Software
FileDescription: Everyday Auto Backup
FileVersion: 1.0.0.38
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Cerbu.148497 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.148497
FireEyeGen:Variant.Cerbu.148497
McAfeeArtemis!C4181BCCB5B2
CylanceUnsafe
SangforTrojan.Win32.Agent.V3ev
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.0de5cadc
K7GWTrojan ( 005722fe1 )
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyTrojan.Win32.Ekstak.amlkh
BitDefenderGen:Variant.Cerbu.148497
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Cerbu.148497
SophosMal/Generic-S
DrWebTrojan.Zadved.1709
VIPREGen:Variant.Cerbu.148497
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Cerbu.148497 (B)
GDataWin32.Backdoor.Bodelph.4VE0GP
JiangminTrojan.Ekstak.bzmx
AviraTR/Drop.Agent.equze
ZoneAlarmTrojan.Win32.Ekstak.amlkh
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Adware-gen.R506212
ALYacGen:Variant.Cerbu.148497
MAXmalware (ai score=83)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CGO22
FortinetW32/Agent.SLC!tr.dldr
AVGWin32:Adware-gen [Adw]

How to remove Cerbu.148497 (B)?

Cerbu.148497 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment