Malware

Cerbu.174323 (B) malicious file

Malware Removal

The Cerbu.174323 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.174323 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Cerbu.174323 (B)?


File Info:

name: 967C2CE4C00E49379023.mlw
path: /opt/CAPEv2/storage/binaries/eb254c1919530eb48bb6b2ea7cbd0082049a6adc6f7b797c9ff0b376da148f11
crc32: 2664BE9C
md5: 967c2ce4c00e4937902378691052ee91
sha1: 6cc5da0194d91cea65e2d00ad103e019ce930d8d
sha256: eb254c1919530eb48bb6b2ea7cbd0082049a6adc6f7b797c9ff0b376da148f11
sha512: 06558e7953e8cb81ecdb9771b7d4826bc328fb833efdb1ccc36bdc3d838208b3eedd9db71067ae015e85fd8606a3e19c190d3ec3fa2fb2d6877fc5b7d1786a5a
ssdeep: 98304:yiTffaIWe9YU++21aQOAX3SA7Hee1YKaYcbBSSAF8lC:3LfaItYUDU3nSA9aYqBvM8Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE0633A456CE8075FEA3CA384D1A05A854F57B71C214C644BFCC7EEC5269F20A8FE19E
sha3_384: ac914bae8153c748fd8ea2dafdb82ed6770ea0be53fcf44081304da5009e00728154a51dfc3b970152051efed98dd566
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: Fes Networking Limited
FileDescription: FileAlyzer (OpenSBI Edition) Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Cerbu.174323 (B) also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.174323
FireEyeGen:Variant.Cerbu.174323
CAT-QuickHealTrojan.Sabsik
ALYacGen:Variant.Cerbu.174323
MalwarebytesAdware.DownloadAssistant
SangforDropper.Win32.Ekstak.Vsqr
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.714a4725
K7GWTrojan ( 005722fe1 )
CyrenW32/ABRisk.RQKL-7286
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyTrojan.Win32.Ekstak.antnh
BitDefenderGen:Variant.Cerbu.174323
AvastWin32:Malware-gen
TencentWin32.Trojan.Ekstak.Cwnw
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Nekark.vbikt
VIPREGen:Variant.Cerbu.174323
TrendMicroTROJ_GEN.R002C0XER23
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.wc
EmsisoftGen:Variant.Cerbu.174323 (B)
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan.Ekstak.chra
AviraTR/AD.Nekark.vbikt
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Cerbu.D2A8F3
ZoneAlarmTrojan.Win32.Ekstak.antnh
GDataGen:Variant.Cerbu.174323
AhnLab-V3Trojan/Win.Malware-gen.R576494
McAfeeArtemis!967C2CE4C00E
MAXmalware (ai score=80)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0XER23
MaxSecureTrojan.Malware.73555928.susgen
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Cerbu.174323 (B)?

Cerbu.174323 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment