Malware

Cerbu.150968 removal instruction

Malware Removal

The Cerbu.150968 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.150968 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Cerbu.150968?


File Info:

name: E12A39C05C9899508CAB.mlw
path: /opt/CAPEv2/storage/binaries/bbeac94ecf4300d4686cb3fa7075ea888fe51db8ee1d3a6063ee8eb74b281448
crc32: 85ED41FC
md5: e12a39c05c9899508cabaa2265215f76
sha1: 71e4ae1609895abe6c916ba0bb0fd61f7c3735a9
sha256: bbeac94ecf4300d4686cb3fa7075ea888fe51db8ee1d3a6063ee8eb74b281448
sha512: e80c80592b7e2afd201c68c1ed633bfdbc79e4e89b1bde18a31803fb1bb2d6609be715041a6ec2df27f833bc2cdb13a8ca3c28696e949e068691e4b948bd0b8d
ssdeep: 196608:nvsTpZ8KsFH7gcvSUV5AkcS/rqzYo0mPipc6vPDWRO:nvsTpZibZvS+5lcS/ezYo0ciS6zWo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1297633B3E6C3B4F2E49046705B90BC042129FF57CB28AE7619CD1B8C4B5B349E5CA769
sha3_384: 160bf26df4b5ade4e0914c4efdd6fc0604bb6ef856f5dc5dfa6ea139a640217c2e5d631d7f8776ea739d180db45bd0b0
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: LionMbg Software
FileDescription: Day3 Auto Backup
FileVersion: 1.0.0.31
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.150968 also known as:

MicroWorld-eScanGen:Variant.Cerbu.150968
FireEyeGen:Variant.Cerbu.150968
ALYacGen:Variant.Cerbu.150968
CylanceUnsafe
VIPREGen:Variant.Cerbu.150968
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.35cbc039
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Ekstak.gen
BitDefenderGen:Variant.Cerbu.150968
AvastWin32:Trojan-gen
TencentWin32.Trojan.Ekstak.Osmw
Ad-AwareGen:Variant.Cerbu.150968
EmsisoftGen:Variant.Cerbu.150968 (B)
DrWebTrojan.Zadved.1709
TrendMicroTROJ_FRS.VSNTGS22
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataGen:Variant.Cerbu.150968
JiangminTrojan.Ekstak.bztr
AviraTR/Drop.Agent.ugymt
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Trojan-gen.C5217705
McAfeeArtemis!E12A39C05C98
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_FRS.VSNTGS22
YandexTrojan.Ekstak!NSZDQWuDq5I
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr.dldr
AVGWin32:Trojan-gen

How to remove Cerbu.150968?

Cerbu.150968 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment