Malware

Cerbu.64645 (B) malicious file

Malware Removal

The Cerbu.64645 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.64645 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
gx1.monerorx.com
a.tomx.xyz
gx1.monerogx.com
wk.monerogx.com

How to determine Cerbu.64645 (B)?


File Info:

crc32: 6BC72849
md5: a53a2df2ce1651d4be209efb7cb57b63
name: A53A2DF2CE1651D4BE209EFB7CB57B63.mlw
sha1: 57a9af938bc99e79967d6d26bc18ea5643185d4c
sha256: c3a306352c2ddc1b184dbb5ea2362acd53ac28bcb6868813c6ed0a7083e9af8c
sha512: 0d88b33838ee1faf0d8dc2a8da2bf51300252495502ac17f7edae4229d9770d00f1faa8a6b1e10565788b2799d165da63ffa545f5fdd9f1c519638274e244de6
ssdeep: 196608:+A/G1zsNLT9EJXniPFahsYJ+AJGh7QaQsnpQRn1XpXmT/6OhIFCfUa9Y/SwaZtWR:66EJiPFaf+kJCFXUpKwaSV7zv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: boy x7248x6743x6240x6709
FileVersion: 2.5.1.7
CompanyName: boy
Comments: HD Audio Backgaround Process
ProductName: HD Audio Backaground Process
ProductVersion: 2.5.1.7
FileDescription: HD Audio Backgdround Process
Translation: 0x0804 0x04b0

Cerbu.64645 (B) also known as:

K7AntiVirusTrojan ( 005246d51 )
DrWebTool.BtcMine.2110
MicroWorld-eScanGen:Variant.Cerbu.64645
CAT-QuickHealHacktool.Flystudio.16558
ALYacGen:Variant.Cerbu.64645
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/CoinMiner.ali1002002
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.38bc99
CyrenW32/S-47c1ea66!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.CAJ
APEXMalicious
TotalDefenseWin32/Oflwr.A!crypt
AvastWin32:HarHarMiner-A [Trj]
ClamAVWin.Coinminer.Generic-7151250-0
GDataGen:Variant.Cerbu.64645
Kasperskynot-a-virus:RiskTool.Win32.BitMiner.sfa
BitDefenderGen:Variant.Cerbu.64645
TencentWin32.Risk.Bitminer.Lkni
Ad-AwareGen:Variant.Cerbu.64645
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureTrojan:W32/DelfInject.R
BitDefenderThetaGen:NN.ZexaF.34100.@t0@aO0pMBbb
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a53a2df2ce1651d4
EmsisoftGen:Variant.Cerbu.64645 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/S-47c1ea66!Eldorado
Endgamemalicious (high confidence)
eGambitUnsafe.AI_Score_100%
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftPUA:Win32/CoinMiner
ArcabitTrojan.Cerbu.DFC85
AegisLabTrojan.Win32.Generic.liRL
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitMiner.gen
AhnLab-V3Malware/Win32.Generic.C3242903
Acronissuspicious
McAfeeArtemis!A53A2DF2CE16
MAXmalware (ai score=83)
MalwarebytesTrojan.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R002H0CCH20
RisingTrojan.CoinMiner!8.30A (CLOUD)
YandexTrojan.Pasta.Gen.1
IkarusWin32.Malware
FortinetW32/Agent.65CA!tr
AVGWin32:HarHarMiner-A [Trj]

How to remove Cerbu.64645 (B)?

Cerbu.64645 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment