Malware

Cerbu.164685 removal tips

Malware Removal

The Cerbu.164685 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.164685 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Cerbu.164685?


File Info:

name: 9D6EAE9795BBC7CD19FB.mlw
path: /opt/CAPEv2/storage/binaries/8839b2a21a8b6c6d6293e7e69f133f31fe47c54937bf8ab3e2f148435ba8722f
crc32: 452AEDE6
md5: 9d6eae9795bbc7cd19fb20db42d5bc17
sha1: 8ec80353881109ec26a6499538f279f9f02bf3de
sha256: 8839b2a21a8b6c6d6293e7e69f133f31fe47c54937bf8ab3e2f148435ba8722f
sha512: ef12d22e5b86b5cfd4517d7b7cc7deb247d2eb13d696f7436767a35b58825234f926984893b83b2a56123cb9dfdedb81a4d6a85c270af519be81881d9e587aa9
ssdeep: 12288:6G/E5SDAZMSduflBjGaFUdvijVPWSWOSRHJ6u1LRZ4suMfOxApqdASYcE0guj0cL:h9iFRHv3Z4sffqdOcHg80Rq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA050104B7488917C17E8AB4887296D043361E069577CF4ABEAE71AE3FBB3424D43797
sha3_384: de232a041f06f130d29c2b7c73023e8192d3dd296b5442d9fb6396dd469055000157b6e156d271ba82ee01dca6e38f94
ep_bytes: ff250020400000000000000000000000
timestamp: 2102-12-17 06:59:56

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: HP Inc.
FileDescription: PasswordManager
FileVersion: 1.0.0.0
InternalName: PasswordManager.exe
LegalCopyright: Copyright © HP Inc. 2023
LegalTrademarks:
OriginalFilename: PasswordManager.exe
ProductName: PasswordManager
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Cerbu.164685 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.164685
SkyhighGenericRXVI-EC!9D6EAE9795BB
McAfeeGenericRXVI-EC!9D6EAE9795BB
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Cerbu.164685
SangforInfostealer.Win32.Agent.Vbzp
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Cerbu.164685
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Cerbu.D2834D
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Stealer.bdcu
AlibabaTrojanPSW:Win32/Stealer.85a653db
AvastWin32:TrojanX-gen [Trj]
RisingStealer.Agent!8.C2 (TFE:C:NIXW2EWsAgG)
EmsisoftGen:Variant.Cerbu.164685 (B)
F-SecureTrojan.TR/Redcap.uomng
ZillyaTrojan.Stealer.Win32.36689
TrendMicroTROJ_GEN.R002C0PAA24
SophosMal/Generic-S
GoogleDetected
AviraTR/Redcap.uomng
Antiy-AVLTrojan/Win32.Sdum
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-PSW.Win32.Stealer.bdcu
GDataGen:Variant.Cerbu.164685
VaristW32/ABRisk.ITSO-6256
AhnLab-V3Trojan/Win.PWS.R556497
ALYacGen:Variant.Cerbu.164685
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PAA24
TencentMalware.Win32.Gencirc.13be979f
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.201007585.susgen
FortinetPossibleThreat
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Cerbu.164685?

Cerbu.164685 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment