Malware

Should I remove “Cerbu.194670”?

Malware Removal

The Cerbu.194670 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.194670 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Cerbu.194670?


File Info:

name: BEDF08946C0C31FC3816.mlw
path: /opt/CAPEv2/storage/binaries/f0086e6dd31a4e00dc0ca23dfaad375cc7ad9ed6e3253305c4d6f64a689b1e28
crc32: EC232284
md5: bedf08946c0c31fc3816386d389a2fea
sha1: 291b5a55ab3a4d31a2c9cb72d9397fe1050de890
sha256: f0086e6dd31a4e00dc0ca23dfaad375cc7ad9ed6e3253305c4d6f64a689b1e28
sha512: 1fa09833afb9882ee35833895472ca6c1b4f3026b39633195f07fdec2a889749810db4ab2e806243b31adaa52a44e2b898b1dc1f4e42152616d2a86892f3d6d2
ssdeep: 196608:L5XAyYbXHafxe4AaM2q5q28RVXjgc/xqGVLwVHQyd:dXn4XnpT8R9ltV2H1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B663383E26DC0BFD469563B8B40E2504E2975688DF034937AAD4EBC27B5F6305873DA
sha3_384: 7e697cbc483c2e77dd894c350b3116b07b7132d074412936a7992232c5c5e82eae0fd7beced60f08efe7545bbe7134b9
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-11-21 16:56:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: DJClub team
FileDescription: MediaClub Setup
FileVersion:
LegalCopyright:
ProductName: MediaClub
ProductVersion:
Translation: 0x0000 0x04b0

Cerbu.194670 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.194670
FireEyeGen:Variant.Cerbu.194670
SkyhighArtemis!Trojan
McAfeeArtemis!BEDF08946C0C
ZillyaTrojan.Ekstak.Win32.74903
AlibabaTrojan:Win32/Ekstak.3dd26673
ArcabitTrojan.Cerbu.D2F86E
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.apuul
BitDefenderGen:Variant.Cerbu.194670
AvastOther:Malware-gen [Trj]
VIPREGen:Variant.Cerbu.194670
EmsisoftGen:Variant.Cerbu.194670 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Ekstak.cihn
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sonbokli.A!cl
ZoneAlarmTrojan.Win32.Ekstak.apuul
GDataWin32.Trojan.Agent.6OVZVP
VaristW32/Ekstak.IU.gen!Eldorado
AhnLab-V3Trojan/Win.DownloadAssistant.R622897
ALYacGen:Variant.Cerbu.194670
MalwarebytesAdware.DownloadAssistant
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Cerbu.194670?

Cerbu.194670 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment