Malware

Cerbu.190164 (file analysis)

Malware Removal

The Cerbu.190164 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.190164 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Cerbu.190164?


File Info:

name: 79DD180648432B448475.mlw
path: /opt/CAPEv2/storage/binaries/3a45ba29e9de97bf24e1f449b8729c35f3ccf1bc657e4aa10e7c40ed09e51660
crc32: D65600F2
md5: 79dd180648432b4484754238280ce274
sha1: b007ae2412210f5cc0d056728b728fef74d6a05a
sha256: 3a45ba29e9de97bf24e1f449b8729c35f3ccf1bc657e4aa10e7c40ed09e51660
sha512: ee5f81c2fcae2dc26ee6be06369ab1bff8d4f618a3fe38500bcb98c01761f5f0a9a0c35f5a518e3935c26229e16d33582c358c26bad8b159cea8a01caac8d835
ssdeep: 24576:f5Cot30yV3FXFd3CKLzHNsfIZWbGy9hUOHM4N1ivRqusLD3nh95EC5TXKAvR5Du:VtkyLTvLzHNsfI+G+hU+M4N1WkVLThnD
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T19B45B02333E6C4B6F6D520718A767B75F3FAE5350936990233401E0E7B73686A72A217
sha3_384: fe3c361862e45a6f860bcdc38ff5eef58d8847fafbddf4cd456fb7d7c3028f2cb16cec63791074deb6bca4651566154e
ep_bytes: 558bec538b5d08568b750c85f6578b7d
timestamp: 2003-06-24 05:20:56

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Visual Basic HTML Editor DLL
FileVersion: 7.00.9064.9607
InternalName: htmed.dll
LegalCopyright: Copyright (C) Microsoft Corp. 1992-2001
OriginalFilename: htmed.dll
ProductName: Microsoft Development Environment
ProductVersion: 7.00.9064.9607
Translation: 0x0409 0x04b0

Cerbu.190164 also known as:

BkavW32.AIDetectMalware
AVGWin32:Patched-AWW [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.190164
VirITWin32.Senoval.A
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Cerbu.190164
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWW [Trj]
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Cerbu.190164 (B)
DrWebWin32.Beetle.4
VIPREGen:Variant.Cerbu.190164
FireEyeGeneric.mg.79dd180648432b44
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Doina.RPX!MTB
ArcabitTrojan.Cerbu.D2E6D4
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Variant.Cerbu.190164
GoogleDetected
AhnLab-V3Trojan/Win.Doina.R607973
ALYacGen:Variant.Cerbu.190164
Cylanceunsafe
IkarusTrojan.Win32.Patched

How to remove Cerbu.190164?

Cerbu.190164 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment