Malware

Cerbu.8679 removal instruction

Malware Removal

The Cerbu.8679 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.8679 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
tpbhumantest.bid
ww12.tpbhumantest.bid
a.tomx.xyz

How to determine Cerbu.8679?


File Info:

crc32: D87F56D6
md5: db8f976ef0dbf98289cadc01c8d114a7
name: DB8F976EF0DBF98289CADC01C8D114A7.mlw
sha1: 4cd1a33206a51302b870aecb6e03b6b8a8b765fd
sha256: dd131733731214b23cc2c11d6a1ddd4d343b4166680d00a3ba2ebed4ac4d1787
sha512: 2ae3772b018b7bc74dfad5221fd7e9ac6d5254df85c425a5d8344f247576f0be9f214819c231e254a7eb7796746f044a3d37d8f85f7ba711ab32decbe42cf664
ssdeep: 96:e0asbs4uBaa2KWEtpxhDWrfSIDbXALDa2:Nbb1a2ytBafVAa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: grab
FileVersion: 1.00
CompanyName: noOrg
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: grab.exe

Cerbu.8679 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan-Downloader ( 004dd93c1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Surveyer.25
ALYacGen:Variant.Cerbu.8679
MalwarebytesMachineLearning/Anomalous.94%
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan-Downloader ( 004dd93c1 )
Cybereasonmalicious.ef0dbf
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanClicker.VB.OJW
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Cerbu.8679
NANO-AntivirusTrojan.Win32.VB.ewxrfz
MicroWorld-eScanGen:Variant.Cerbu.8679
Ad-AwareGen:Variant.Cerbu.8679
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.mz
FireEyeGen:Variant.Cerbu.8679
EmsisoftGen:Variant.Cerbu.8679 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1107785
Antiy-AVLTrojan/Generic.ASMalwS.23F8FC5
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Cerbu.8679
AhnLab-V3Malware/Win32.Generic.R217269
McAfeeArtemis!DB8F976EF0DB
MAXmalware (ai score=97)
VBA32Trojan.Surveyer
IkarusTrojan.Win32.TrojanClicker
FortinetW32/Generic.AC.2F5D9!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Cerbu.8679?

Cerbu.8679 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment