Malware

Cerbu.28086 removal

Malware Removal

The Cerbu.28086 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.28086 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Cerbu.28086?


File Info:

name: 8B13A2990BB83D4088C4.mlw
path: /opt/CAPEv2/storage/binaries/c158269a99e0c3acf33458059b848fb1b3ceb585884fb6fbeb8e9d4fbc049f91
crc32: 63C12F2C
md5: 8b13a2990bb83d4088c42a09976bd335
sha1: c4c7ba48aaba08f60596a20f9b22f2173e6c2dab
sha256: c158269a99e0c3acf33458059b848fb1b3ceb585884fb6fbeb8e9d4fbc049f91
sha512: 19efbea02a9eb90d30c20c6a168a541f890da72eec41bafbb2b23449947ad7166c587f457b1bf09b74fd00253b3d1b167552917c3721a9272124ddd21b2eb010
ssdeep: 3072:JZiUdUG8ap4yboxBzZ3G2ZHCR7bkO/F4ATL0Xja6eWOT:JZiLzyohIgi2Od4A5X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2F3CF12B2D0C471E5B7093914F4AAB98D2DBA261F70DCBB2794277E4F308D15A35E2E
sha3_384: 1ce73c900fa76dec4d64a7334657a8e29dc00e68237e614ba039eaa74236a96dc41a6008ff6479b20543812cd5ef62d2
ep_bytes: e808040000e97afeffff558bec56ff75
timestamp: 2019-03-12 14:21:32

Version Info:

CompanyName: Microsoft
FileDescription: Windows Security Watcher
FileVersion: 2, 17,0,443
InternalName: Windows Security Watcher
LegalCopyright: Mictosoft
OriginalFilename: WUDHOST
ProductName: Windows Security Watcher
ProductVersion: 2.17.0.443
Translation: 0x0409 0x04b0

Cerbu.28086 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Cerbu.28086
FireEyeGeneric.mg.8b13a2990bb83d40
ALYacGen:Variant.Cerbu.28086
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054189e1 )
K7GWTrojan ( 0054189e1 )
Cybereasonmalicious.90bb83
ArcabitTrojan.Cerbu.D6DB6
BitDefenderThetaGen:NN.ZexaF.34742.ju0@a0pK3ndc
CyrenW32/S-4c333de1!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.CORV
ClamAVWin.Malware.Cerbu-9950532-0
KasperskyTrojan.Win32.Agentb.jlyf
BitDefenderGen:Variant.Cerbu.28086
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.1169738c
Ad-AwareGen:Variant.Cerbu.28086
SophosGeneric ML PUA (PUA)
ZillyaTrojan.Agentb.Win32.22168
McAfee-GW-EditionGenericRXGU-QD!8B13A2990BB8
EmsisoftGen:Variant.Cerbu.28086 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.MSIL.bwuo
AviraHEUR/AGEN.1213142
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Cerbu.28086
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Blocker.R271796
Acronissuspicious
McAfeeGenericRXGU-QD!8B13A2990BB8
VBA32Trojan.Agentb
MalwarebytesMachineLearning/Anomalous.96%
APEXMalicious
RisingTrojan.Generic@AI.95 (RDMK:hG7GgWjPD1+umIZ2DOHqQw)
YandexTrojan.GenAsa!v6p8XnZfBw4
MaxSecureTrojan.Malware.74562586.susgen
FortinetW32/Generic.AC.437CA5
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Cerbu.28086?

Cerbu.28086 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment