Malware

About “Cerbu.64645” infection

Malware Removal

The Cerbu.64645 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.64645 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

gx1.monerorx.com
rx.monerorx.com

How to determine Cerbu.64645?


File Info:

crc32: 6BC72849
md5: a53a2df2ce1651d4be209efb7cb57b63
name: wk.exe
sha1: 57a9af938bc99e79967d6d26bc18ea5643185d4c
sha256: c3a306352c2ddc1b184dbb5ea2362acd53ac28bcb6868813c6ed0a7083e9af8c
sha512: 0d88b33838ee1faf0d8dc2a8da2bf51300252495502ac17f7edae4229d9770d00f1faa8a6b1e10565788b2799d165da63ffa545f5fdd9f1c519638274e244de6
ssdeep: 196608:+A/G1zsNLT9EJXniPFahsYJ+AJGh7QaQsnpQRn1XpXmT/6OhIFCfUa9Y/SwaZtWR:66EJiPFaf+kJCFXUpKwaSV7zv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: boy x7248x6743x6240x6709
FileVersion: 2.5.1.7
CompanyName: boy
Comments: HD Audio Backgaround Process
ProductName: HD Audio Backaground Process
ProductVersion: 2.5.1.7
FileDescription: HD Audio Backgdround Process
Translation: 0x0804 0x04b0

Cerbu.64645 also known as:

DrWebTool.BtcMine.2110
MicroWorld-eScanGen:Variant.Cerbu.64645
CAT-QuickHealHacktool.Flystudio.16558
Qihoo-360Win32/Virus.RiskTool.ab2
McAfeeArtemis!A53A2DF2CE16
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Cerbu.64645
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.38bc99
BitDefenderThetaGen:NN.ZexaF.34100.@t0@aO0pMBbb
CyrenW32/S-47c1ea66!Eldorado
TotalDefenseWin32/Oflwr.A!crypt
APEXMalicious
AvastWin32:HarHarMiner-A [Trj]
ClamAVWin.Coinminer.Generic-7151250-0
GDataGen:Variant.Cerbu.64645
Kasperskynot-a-virus:RiskTool.Win32.BitMiner.sfa
AlibabaTrojan:Win32/CoinMiner.ali1002002
AegisLabTrojan.Win32.Generic.liRL
TencentWin32.Risk.Bitminer.Lkni
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Cerbu.64645 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureTrojan:W32/DelfInject.R
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a53a2df2ce1651d4
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
F-ProtW32/S-47c1ea66!Eldorado
AviraTR/CoinMiner.zgyet
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftPUA:Win32/CoinMiner
ArcabitTrojan.Cerbu.DFC85
ZoneAlarmnot-a-virus:RiskTool.Win32.BitMiner.sfa
AhnLab-V3Malware/Win32.Generic.C3242903
Acronissuspicious
ALYacGen:Variant.Cerbu.64645
MAXmalware (ai score=83)
Ad-AwareGen:Variant.Cerbu.64645
MalwarebytesTrojan.BitCoinMiner
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/CoinMiner.CAJ
TrendMicro-HouseCallTROJ_GEN.R002H0CCH20
RisingTrojan.CoinMiner!8.30A (CLOUD)
YandexTrojan.Pasta.Gen.1
IkarusWin32.Malware
eGambitUnsafe.AI_Score_100%
FortinetW32/Agent.65CA!tr
AVGWin32:HarHarMiner-A [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Cerbu.64645?

Cerbu.64645 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment