Malware

What is “Cerbu.76500 (B)”?

Malware Removal

The Cerbu.76500 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.76500 (B) virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

dasan.sejong.ac.kr
www.aviafilm.com.ua

How to determine Cerbu.76500 (B)?


File Info:

crc32: 961B995C
md5: d5d777d097f022b37071f030b77379f4
name: D5D777D097F022B37071F030B77379F4.mlw
sha1: 14f416f919dfcdbbb7de53667be24a7a8b096d79
sha256: bcfd2404f11c6f0d99b3d2adabb83fad7eb52068718c8707f31be7c23e9906cf
sha512: 7b81a0d03d78d6e5d81e82cf95452f9ad3c8a9e6c713815f0a8be15aa80bb6335c67299242d5abfe08e2023cf7e814811b1fe7d492749e6e8a7afdcdda9f47db
ssdeep: 3072:LqSLIAh55+9TIjx2r55rDaIGfelcHxM230ArAgcxKt3XB59U6:+S8Ah55+9TIjylcHe237HSkR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: jvtd64
FileVersion: 1.00
CompanyName: jvtd64
ProductName: jvtd64
ProductVersion: 1.00
OriginalFilename: jvtd64.exe

Cerbu.76500 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusNetWorm ( 700000151 )
LionicTrojan.Win32.Cossta.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Cerbu.76500
ZillyaTrojan.Cossta.Win32.10132
CrowdStrikewin/malicious_confidence_70% (D)
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.097f02
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Bancos.ACM
APEXMalicious
AvastWin32:GenMalicious-XO [Trj]
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Cossta.ajxm
BitDefenderGen:Variant.Cerbu.76500
NANO-AntivirusTrojan.Win32.Cossta.emtepe
MicroWorld-eScanGen:Variant.Cerbu.76500
TencentWin32.Trojan.Cossta.Wtdn
Ad-AwareGen:Variant.Cerbu.76500
SophosML/PE-A
ComodoMalware@#8qfyc5nm0ioy
BitDefenderThetaGen:NN.ZevbaF.34050.km0@aShJmiii
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
FireEyeGeneric.mg.d5d777d097f022b3
EmsisoftGen:Variant.Cerbu.76500 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Cossta.tw
AviraHEUR/AGEN.1116360
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.1F10EA3
KingsoftWin32.Troj.Cossta.aj.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
GDataGen:Variant.Cerbu.76500
AhnLab-V3Trojan/Win32.Bancos.R142550
McAfeeGenericRXAA-AA!D5D777D097F0
MAXmalware (ai score=82)
VBA32Trojan.Cossta
PandaTrj/GdSda.A
YandexTrojan.GenAsa!8L93Tqeiayk
IkarusTrojan.Win32.Cossta
FortinetW32/Bancos.ACMB!tr
AVGWin32:GenMalicious-XO [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.FRS.HgIASOoA

How to remove Cerbu.76500 (B)?

Cerbu.76500 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment