Malware

Cerbu.80030 information

Malware Removal

The Cerbu.80030 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.80030 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Attempted to write to a harddisk volume
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Cerbu.80030?


File Info:

name: A7F7D4D5ADFDEF88BE1A.mlw
path: /opt/CAPEv2/storage/binaries/e632d2d33603f4084f1ebc80b125697eeaee518993aa26924745cd53f74b73d8
crc32: 39AC6E1A
md5: a7f7d4d5adfdef88be1ab98247a564c0
sha1: 0b50737cde4b7c4c96e82df6d37b3e8a11a20fba
sha256: e632d2d33603f4084f1ebc80b125697eeaee518993aa26924745cd53f74b73d8
sha512: cb75d2ed1fc51ca9b3f3ce0001167b65524860d3954642a191b6a2361493ed375667f09561caac3592b979ed52d5a0681b14560466448fcfecc06b6e93a152dc
ssdeep: 3072:wZeRGji3vIUTvU6AYSumhiYYwysO6vs7pUMNLAh/DFQDAHdBz/rJuy7NqL4P8h:w4KbG4+wysO4IAhHdBz/R7NqU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FD30219B37A151AE95713781A372AA11CF7AD104BB54BCB2514AE4BDEAE3C1CE30F03
sha3_384: e277297709f8fd5c086ef9ed12f2f44bd1434e4915d7014176577de22a11e5658726b07ed99eac3f8aeb153a85f1ab0d
ep_bytes: 6a00488b042483c4048d14388d043031
timestamp: 2013-09-06 16:31:50

Version Info:

CompanyName: Apache Software Foundation
FileDescription: ApacheBench command line utility
FileVersion: 2.4.3
InternalName: ab.exe
LegalCopyright: Copyright 2012 The Apache Software Foundation.
OriginalFilename: ab.exe
ProductName: Apache HTTP Server
ProductVersion: 2.4.3
Translation: 0x0409 0x04b0

Cerbu.80030 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.80030
FireEyeGeneric.mg.a7f7d4d5adfdef88
CAT-QuickHealTrojan.Sirefef.Gen
SkyhighBehavesLike.Win32.Ramnit.cc
McAfeeZeroAccess-FBE!A7F7D4D5ADFD
Cylanceunsafe
ZillyaTrojan.Sirefef.Win32.7630
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00457e8e1 )
AlibabaVirTool:Win32/Obfuscator.648a8cf5
K7GWTrojan ( 00457e8e1 )
Cybereasonmalicious.cde4b7
VirITTrojan.Win32.Generic.CUH
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Sirefef.FY
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Cerbu.80030
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Sirefef-BUO [Drp]
TencentWin32.Trojan.Generic.Ssmw
EmsisoftGen:Variant.Cerbu.80030 (B)
F-SecureBackdoor.BDS/ZeroAccess.Gen7
DrWebBackDoor.Maxplus.12847
VIPREGen:Variant.Cerbu.80030
TrendMicroTROJ_SPNR.35JA13
Trapminemalicious.high.ml.score
SophosTroj/ZAccess-PI
IkarusBackdoor.Win32.ZAccess
GDataGen:Variant.Cerbu.80030
JiangminTrojan.Generic.hpefv
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraBDS/ZeroAccess.Gen7
Antiy-AVLTrojan[Backdoor]/Win32.ZAccess
Kingsoftmalware.kb.a.956
XcitiumTrojWare.Win32.Kryptik.BJS@51lbut
ArcabitTrojan.Cerbu.D1389E
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sirefef.P
VaristW32/A-ec385fc7!Eldorado
AhnLab-V3Trojan/Win32.ZAccess.R81681
VBA32Backdoor.ZAccess
ALYacGen:Variant.Cerbu.80030
MAXmalware (ai score=100)
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.35JA13
RisingTrojan.Toga!8.136D (TFE:1:cii28QrXkUB)
YandexTrojan.GenAsa!xDe1jPHJYO0
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ZeroAccess.FB!tr
BitDefenderThetaGen:NN.ZexaF.36744.iq0@aC47Z5mi
AVGWin32:Sirefef-BUO [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Cerbu.80030?

Cerbu.80030 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment