Malware

Cerbu.151540 removal tips

Malware Removal

The Cerbu.151540 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.151540 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Cerbu.151540?


File Info:

name: D774D5AD5970854BE413.mlw
path: /opt/CAPEv2/storage/binaries/e5150660a96c800929684efb4d94876b49884b282f299617d82eb980609fbc3b
crc32: 9667DBA6
md5: d774d5ad5970854be413a29661586718
sha1: 617104b5e7c78da9f2e8ec50995797acf1bb73e1
sha256: e5150660a96c800929684efb4d94876b49884b282f299617d82eb980609fbc3b
sha512: 86cdf693139f521efd845854d91b4288dad1366cc2799ac3e2a314510fa60ebb34b91c0fb83268e6ff99fe8ddfef182e22843112e6ab280b77d3896924ac1930
ssdeep: 98304:diuc4ocTfkfyU9UUlUUJUUUUUUUUUUUUUUUwUUUUUn5aIX3AornHUfPfDeYs615p:E54ocTfNU9UUlUUJUUUUUUUUUUUUUUUy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1880622547710DEF0F8BC0433A8B44F581216FF29A85155DBACD8769A8D2B883E316ADF
sha3_384: 71782a9076a9e8a0cf9db85c8cbf8a51dc39f7b8d61ab9aa66aed481cc9f7268831c587369e5a3c4165e817c1bab283b
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: STARMASTER6
FileDescription: GladiolusFiles Pro
FileVersion: 1.0.0.2
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Cerbu.151540 also known as:

LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (moderate confidence)
CynetMalicious (score: 99)
FireEyeGen:Variant.Cerbu.151540
McAfeeArtemis!D774D5AD5970
CylanceUnsafe
SangforTrojan.Win32.Agent.V57i
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.c37b46ed
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.CX.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
ClamAVWin.Malware.Adwarex-9965264-0
KasperskyTrojan.Win32.Ekstak.amqzb
BitDefenderGen:Variant.Cerbu.151540
MicroWorld-eScanGen:Variant.Cerbu.151540
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Ekstak.Rsmw
Ad-AwareGen:Variant.Cerbu.151540
EmsisoftGen:Variant.Cerbu.151540 (B)
GDataGen:Variant.Cerbu.151540
JiangminTrojan.Ekstak.cbgw
AviraTR/Drop.Agent.qtshu
MAXmalware (ai score=86)
ArcabitTrojan.Cerbu.D24FF4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Dropper/Win.InnoSetup.C5228775
ALYacGen:Variant.Cerbu.151540
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CHR22
AVGWin32:AdwareX-gen [Adw]

How to remove Cerbu.151540?

Cerbu.151540 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment