Malware

Cerbu.70201 removal

Malware Removal

The Cerbu.70201 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.70201 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Cerbu.70201?


File Info:

name: 4B6CE074930CF4CB084C.mlw
path: /opt/CAPEv2/storage/binaries/cdfaac86d47934208c5cc2f5620f631dcc1c8fec0cdad26dc80d14184a38697f
crc32: 07BEDA9E
md5: 4b6ce074930cf4cb084c71ca7065001f
sha1: f3dccde6843f5826a437deaca5124716fceb1fac
sha256: cdfaac86d47934208c5cc2f5620f631dcc1c8fec0cdad26dc80d14184a38697f
sha512: d7f237e440697d780d48bbb4d852132fd2bba047cd65e5980ccd77393428894a21a54889520a17e424431f7aa94a6034e8eb6a1fc654a5427f99341d3122b54c
ssdeep: 3072:+QLSulBc36Q+IJphdiZBevoKWS+WkygLe/d1Pgcr7egiBUljEL6d:NLi6C/AZ0oPPTy5/d/eg0m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160244C36E5A2A152EAA101F25C6665FC1E382C3481C6BE1331D06E48DD76E3BB9DC377
sha3_384: f271e5ea986b3ab51288c827b62da4fe6cdf2edca986489294cf6e5d4f5d47489f92d69d82a775964686784c5331f519
ep_bytes: 681c504000e8eeffffff000040000000
timestamp: 2006-08-11 10:46:15

Version Info:

Translation: 0x0412 0x04b0
CompanyName: ILOVEVB
LegalCopyright: 밤하늘
ProductName: 런타임
FileVersion: 1.00
ProductVersion: 1.00
InternalName: runtime
OriginalFilename: runtime.dll

Cerbu.70201 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.70201
FireEyeGeneric.mg.4b6ce074930cf4cb
McAfeeGenericR-JRO!4B6CE074930C
CylanceUnsafe
ZillyaAdware.BetterSurf.Win32.12042
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZevbaF.34786.nm3@aWDkKEnG
tehtrisGeneric.Malware
Paloaltogeneric.ml
ClamAVWin.Trojan.Johnnie-7165564-0
BitDefenderGen:Variant.Cerbu.70201
NANO-AntivirusTrojan.Win32.VB.esnrku
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114cdf8b
Ad-AwareGen:Variant.Cerbu.70201
EmsisoftGen:Variant.Cerbu.70201 (B)
VIPREGen:Variant.Cerbu.70201
McAfee-GW-EditionGenericR-JRO!4B6CE074930C
SentinelOneStatic AI – Suspicious PE
IkarusTrojan.Dropper
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3E79
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Cerbu.D11239
GDataGen:Variant.Cerbu.70201
CynetMalicious (score: 99)
VBA32Trojan.VBKrypt
ALYacGen:Variant.Cerbu.70201
APEXMalicious
YandexTrojan.VbCrypt!2TAgOKWQ5Hs
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.4930cf

How to remove Cerbu.70201?

Cerbu.70201 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment