Malware

Cerbu.149810 removal guide

Malware Removal

The Cerbu.149810 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.149810 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk

How to determine Cerbu.149810?


File Info:

name: 2849FA50AFB7EC9691E9.mlw
path: /opt/CAPEv2/storage/binaries/0edd8b08a10c8a0a77f78066b800a8dcfff4603f4492a588d632fe0e2ee6cbc2
crc32: 8484459C
md5: 2849fa50afb7ec9691e9a7b420c4d1c1
sha1: 8296eb91fbf028837e45457fcb17b77ff3dd99a0
sha256: 0edd8b08a10c8a0a77f78066b800a8dcfff4603f4492a588d632fe0e2ee6cbc2
sha512: 0ec786eb37afffa4795ec37be88ef5926531d2cf70cb3fd5fd83e6fbed664657bf6901ef4a3c92fe8597ad6d0302e294d583b6ab5b7a17e823e75176f8bd64d4
ssdeep: 196608:noOrXZVusuqMr5pk9eVSdIJ2SNzzJyPIYVisdGldT:n1JVusuqkTweYdkJZFyPIYVjGz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A763344F1C091FED06E4B714C22EEB810257E1E3EB1D68EB56F35AF6B3E2E21516648
sha3_384: 4562ea76aaee930dd01ac47b06594ceb75e6f4c11f9debfb35a9a35488d7b5d91d872659f7e5d82699ef57076ef7073b
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: BitABE
FileDescription: UndeleteMyFiles Pro Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Cerbu.149810 also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.149810
FireEyeGen:Variant.Cerbu.149810
ALYacGen:Variant.Cerbu.149810
CylanceUnsafe
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.54fee60e
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0CGV22
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.ammvu
BitDefenderGen:Variant.Cerbu.149810
NANO-AntivirusTrojan.Win32.Ekstak.jrikqy
CynetMalicious (score: 100)
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Ekstak.Ddhl
Ad-AwareGen:Variant.Cerbu.149810
EmsisoftGen:Variant.Cerbu.149810 (B)
VIPREGen:Variant.Cerbu.149810
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.SZV044
JiangminTrojan.Ekstak.bzts
AviraTR/Drop.Agent.zgwdu
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R508951
MalwarebytesAdware.DownloadAssistant
MaxSecureTrojan.Malware.186406788.susgen
FortinetW32/Agent.SLC!tr.dldr
AVGWin32:MalwareX-gen [Trj]

How to remove Cerbu.149810?

Cerbu.149810 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment