Malware

Cerbu.74410 removal instruction

Malware Removal

The Cerbu.74410 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.74410 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Cerbu.74410?


File Info:

name: E143466E744DDA553B5B.mlw
path: /opt/CAPEv2/storage/binaries/fff7fe1dec2520136dd45fa2f01126d331dc56fc1e453a8e55dc7adaebea6724
crc32: 64DC61D6
md5: e143466e744dda553b5b697f68094a4c
sha1: 0c0ece9c0f8d00d2944f062d4e45224f5761766e
sha256: fff7fe1dec2520136dd45fa2f01126d331dc56fc1e453a8e55dc7adaebea6724
sha512: f6f9d48a1aa8fcacef5ae779f1e6643605e43132ff08d5925d9cc521e18ff1117074400727718ba08c547711fb6b8b14835f9837fb139b577310c09af3629c71
ssdeep: 3072:wCTz/r1wCVdQEdrxgyc7OHdXK1FzhXULuPDC:d3zrXQEdxgG4kLuPD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16ED3D015BA0AF2EBF5BBD0F63297F39A7B38D910A304780F1699A5C7A827074425D743
sha3_384: e0d2096bfb962d865da5d059822fff78d6d128ed88a8cc9f4cac382b2deb39022a4c2f71fbafe2cf44cfbccf0cf0c561
ep_bytes: 8915a1c04100893d60c04100891d4fc0
timestamp: 1992-06-19 22:22:17

Version Info:

FileDescription: Downloader
FileVersion: 1, 0, 0, 0
InternalName: Downloader
LegalCopyright: Copyright 2013
OriginalFilename: Downloader.exe
ProductName: Downloader
ProductVersion: 1, 0, 0, 0
Translation: 0x0419 0x04e3

Cerbu.74410 also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.LMN.1!c
MicroWorld-eScanGen:Variant.Cerbu.74410
ClamAVWin.Trojan.Loadmoney-11772
FireEyeGeneric.mg.e143466e744dda55
CAT-QuickHealTrojan.Sisproc.A6
McAfeeDownloader-FWY!E143466E744D
CylanceUnsafe
VIPREGen:Variant.Cerbu.74410
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005042e41 )
AlibabaTrojan:Win32/Kryptik.805c85bc
K7GWTrojan ( 005042e41 )
Cybereasonmalicious.e744dd
BaiduWin32.Adware.Kryptik.c
CyrenW32/LoadMoney.L.gen!Eldorado
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BVGB
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.LMN.wn
BitDefenderGen:Variant.Cerbu.74410
NANO-AntivirusTrojan.Win32.LMN.dkpvah
SUPERAntiSpywareTrojan.Agent/Gen-Ogimant
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b403e4
Ad-AwareGen:Variant.Cerbu.74410
TACHYONTrojan/W32.Agent.134656.AAD
EmsisoftGen:Variant.Cerbu.74410 (B)
ComodoTrojWare.Win32.Kryptik.BNMK@54af98
DrWebTrojan.LoadMoney.225
TrendMicroTROJ_GEN.R067C0CJ522
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.high.ml.score
SophosMal/EncPk-ACB
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Cerbu.74410
JiangminTrojan/Badur.aqt
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.30B0
KingsoftWin32.Troj.DownLMN.wn.(kcloud)
ViRobotTrojan.Win32.Generic.138160
MicrosoftTrojan:Win32/Senta!rfn
GoogleDetected
AhnLab-V3Trojan/Win32.LoadMoney.C219100
BitDefenderThetaAI:Packer.852C051E21
ALYacGen:Variant.Cerbu.74410
MAXmalware (ai score=89)
VBA32Malware-Cryptor.Limpopo
MalwarebytesPUP.Optional.LoadMoney
TrendMicro-HouseCallTROJ_GEN.R067C0CJ522
RisingAdware.LoadMoney!1.AE7B (CLASSIC)
YandexTrojan.GenAsa!r14VqVUudX8
IkarusWin32.Outbreak
FortinetRiskware/LMN
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Cerbu.74410?

Cerbu.74410 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment