Malware

What is “Cerbu.202010”?

Malware Removal

The Cerbu.202010 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.202010 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine Cerbu.202010?


File Info:

name: E5C414E3A37737D76882.mlw
path: /opt/CAPEv2/storage/binaries/d4a640877a4df47d3db676c918869447b458033531f1b7c91b4ba2d79232c18a
crc32: 5E6C2023
md5: e5c414e3a37737d76882b83efbcb2cc1
sha1: 44c8c88e0e84f2914fa78e686098fe3b471b0f14
sha256: d4a640877a4df47d3db676c918869447b458033531f1b7c91b4ba2d79232c18a
sha512: 3c703e66866b23764598eb1e9536022fc75684a179a3cfe19c10947e729d67f5636ce8a9026fba50fcb6fb729066732400b86d90db1d76bae9320fc5a3ace0a6
ssdeep: 192:+vxJqAPhpeS1ZK4O3CDHp1QyJXzMYu+KYp5U4ubvRxK:4UAPk21QGMn+KYpu4uFQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B32D900BC419A24E5E384B84571D396F86C2E340369A5E343F3BC879CB96D1333CA5B
sha3_384: 86c59893f667ecceaf5268150d2b99faf11ae724e026ac021887326e512c558a2ad437aef9ef313db82554fe8968d983
ep_bytes: 558bec68f0134000e8d3ffffff83c404
timestamp: 1970-02-28 08:42:04

Version Info:

0: [No Data]

Cerbu.202010 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vtflooder.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Cerbu.202010
FireEyeGeneric.mg.e5c414e3a37737d7
McAfeeGenericRXGG-SY!E5C414E3A377
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Vtflooder.Win32.915
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a74e21 )
AlibabaTrojan:Win32/Vtflooder.493
K7GWTrojan ( 005a74e21 )
Cybereasonmalicious.3a3773
BitDefenderThetaGen:NN.ZexaF.36802.amW@aajqC5d
SymantecDownloader.Upatre
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanClicker.Tiny.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vtflooder.cft
BitDefenderGen:Variant.Cerbu.202010
NANO-AntivirusTrojan.Win32.Crypted.dbpklq
SUPERAntiSpywareTrojan.Agent/Gen-Vtflooder
RisingTrojan.Vflooder!1.A171 (CLASSIC)
TACHYONTrojan/W32.Vtflooder.11776
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Flood.22062
VIPREGen:Variant.Cerbu.202010
TrendMicroTrojan.Win32.VFLOODER.SM
Trapminemalicious.high.ml.score
SophosTroj/Agent-AHNL
IkarusTrojan.Win32.TrojanClicker
JiangminTrojan/Badur.cky
AviraTR/Crypt.XPACK.Gen
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumTrojWare.Win32.TrojanDownloader.Tiny.N@7sc62q
ArcabitTrojan.Cerbu.D3151A
ZoneAlarmTrojan.Win32.Vtflooder.cft
GDataWin32.Trojan.PSE.16MMF44
VaristW32/Agent.CFW.gen!Eldorado
AhnLab-V3Trojan/Win32.RL_Vtflooder.R273172
Acronissuspicious
VBA32Trojan.Badur
ALYacGen:Variant.Cerbu.202010
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTrojan.Win32.VFLOODER.SM
TencentTrojan.Win32.VtFlooder.a
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Badur.ilcp
FortinetW32/Agent.D382!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan:Win/Vflooder.A(dyn)

How to remove Cerbu.202010?

Cerbu.202010 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment