Malware

What is “Cerbu.186937”?

Malware Removal

The Cerbu.186937 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.186937 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Cerbu.186937?


File Info:

name: 5275B846F98D7A5FA76F.mlw
path: /opt/CAPEv2/storage/binaries/5700d6209d421a8d4f8f1876f9d95cc171766d551c35738fb211d7806f38161b
crc32: DA63D8C5
md5: 5275b846f98d7a5fa76f83375c5afc96
sha1: 45bef291c4f7e149dd637949322115f2d0eac4ec
sha256: 5700d6209d421a8d4f8f1876f9d95cc171766d551c35738fb211d7806f38161b
sha512: 267cd662420b971a3ecef16f31d315ebdccbd9ea0154c58f61449ce275aff775f067aa97f8f657813c7de5554dfd66892c6dfcd95145400f05857ca12dc164bf
ssdeep: 1536:h7PWNWsB7qhuu9y2/vzCPE3yQnV07hMX8ZmWH:x4BIuu9y23gEymPw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B063A313A210CC72F0590270D5B75BA4EB34AFA5B971472BEB807DB46EB6B319F4681C
sha3_384: 0b6daeb2a1fc80c8a8beb9e7fd79402878c160c77fa6933d7d4b60cc1c86006d7791eae26a62e1a67fc25e0d7fd0c4c8
ep_bytes: e80600000050e8bb010000558bec81c4
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 1.0.0.0
FileDescription: tEmpEr
ProductName: 幽灵网吧辅助工具 v4.0
ProductVersion: 1.0.0.0
CompanyName: 泆寒
LegalCopyright: 泆寒 版权所有
Comments: www.netbartool.com www.netbarghost.com by:yhan
Translation: 0x0804 0x04b0

Cerbu.186937 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Cerbu.186937
FireEyeGeneric.mg.5275b846f98d7a5f
ALYacTrojan.GenericKDZ.102432
MalwarebytesTrojan.FlyStudio
Cybereasonmalicious.1c4f7e
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Cerbu.186937
TACHYONTrojan/W32.Agent.70656.AHY
VIPRETrojan.GenericKDZ.102432
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminRiskTool.FlyStudio.acl
WebrootW32.Allaple.Gen
Kingsoftmalware.kb.a.1000
GridinsoftRansom.Win32.Wacatac.sa
XcitiumTrojWare.Win32.FlyStudio.~UJ@1sa9s6
ArcabitTrojan.Generic.D19020
GoogleDetected
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
Cylanceunsafe
RisingStealer.QQPass!1.648F (CLASSIC)
IkarusWorm.SuspectCRC
CrowdStrikewin/grayware_confidence_60% (W)

How to remove Cerbu.186937?

Cerbu.186937 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment