Malware

Cerbu.161072 removal tips

Malware Removal

The Cerbu.161072 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.161072 virus can do?

  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Cerbu.161072?


File Info:

name: BE392A387407E5A5F176.mlw
path: /opt/CAPEv2/storage/binaries/10b16776cbbc32e536b3232181b38a1f343f2e888ba99476098cfc29b73f1c43
crc32: B47DF112
md5: be392a387407e5a5f17689ff1c50ba8d
sha1: d6b2616aab89ebadc0819a078e7c55ab64bceab3
sha256: 10b16776cbbc32e536b3232181b38a1f343f2e888ba99476098cfc29b73f1c43
sha512: c736258067c41169c6969ebec7822608f7619f51a6a4edd3286121172da4f6fc5e7b381c33c04f16e58521b6564c53a7b8fe115758d8f6fe9adea0d51fe4e3c6
ssdeep: 49152:a5mLAC3+sF56HC5oM8THPTRWEOzj6lxWC1p3kOj:a5mL7uS8TdWEW6l
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T120C5BF02FB8295F2D8D7027912E757BF1E3959189734CAC3CBA119BA8C216D1673F398
sha3_384: 56f0c86b7ba01108ec2f18a66172f0f36c116d80e4f6bd98299ba872eac5a7c79e3bd65d4d52387fcc1773818d36803a
ep_bytes: e8490a0000e974feffffcccccccccccc
timestamp: 2023-01-12 13:48:10

Version Info:

0: [No Data]

Cerbu.161072 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
MicroWorld-eScanGen:Variant.Cerbu.161072
ALYacGen:Variant.Cerbu.161072
MalwarebytesMalware.AI.3517697181
ZillyaTrojan.Convagent.Win32.10684
SangforTrojan.Win32.Agent.Vioa
AlibabaTrojan:Win32/Generic.56878c97
CyrenW32/Agent.FOQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.AFBO
CynetMalicious (score: 99)
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Cerbu.161072
NANO-AntivirusTrojan.Win32.Scar.juhnol
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Cerbu.161072 (B)
F-SecureTrojan.TR/Agent.kaafi
DrWebTrojan.Siggen19.28402
VIPREGen:Variant.Cerbu.161072
McAfee-GW-EditionBehavesLike.Win32.BadFile.vh
FireEyeGen:Variant.Cerbu.161072
SophosMal/Generic-S
GDataGen:Variant.Cerbu.161072
JiangminTrojan.Scar.uye
AviraTR/Agent.kaafi
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Convagent
ArcabitTrojan.Cerbu.D27530
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R553183
McAfeeGenericRXAA-FA!BE392A387407
VBA32BScope.Trojan.Convagent
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CAE23
RisingTrojan.Agent!8.B1E (TFE:5:8IbPD4aRrjD)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.AFBO!tr
BitDefenderThetaGen:NN.ZexaE.36196.JwW@aSItGrci
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Cerbu.161072?

Cerbu.161072 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment