Malware

What is “Cerbu.91704”?

Malware Removal

The Cerbu.91704 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.91704 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Cerbu.91704?


File Info:

crc32: 89F307F4
md5: 1c97fda2bc2d3a20d4026b906284a216
name: 1C97FDA2BC2D3A20D4026B906284A216.mlw
sha1: 16de85089bba3f4652f7fd64774d262d7b80b0e2
sha256: 86b22d8497ac1df55b76bddca6c021ec4b9995b00caea5effeeffe4e9f592e44
sha512: b99745e0bdf586d5536bd1db2cec95b4349181e8d3217fabbc48b9b9bd1488384839d09745598afdc33d2807cc5446b3723f910c34a70d43e3aa759bde0a8cc3
ssdeep: 3072:5f1BDZ0kVB67Duw9AMc4b9oSeNfBvImJHXeFuJFuzZKXlxQuTOGPfvIIU8KHv5dE:59X0GScVZdPIzQxQ+nJqu71pJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Copyright Dagoman
FileVersion: 12.49.98.24
CompanyName: Dravidian Unclassified
LegalTrademarks: Republic of Cape Verde
Comments: empty
ProductName: cinder track
FileDescription: Rumantsch Grischun
Translation: 0x0409 0x04e4

Cerbu.91704 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.91704
FireEyeGeneric.mg.1c97fda2bc2d3a20
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Androm.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Cerbu.91704
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2bc2d3
CyrenW32/Injector.AEY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EORU
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
KasperskyTrojan.Win32.Agent.xahazp
AlibabaTrojan:Win32/Androm.69611275
NANO-AntivirusTrojan.Win32.Inject.imohvn
RisingTrojan.Generic@ML.80 (RDML:pVqKRAFeXz8WcqwPBwF9Gw)
SophosML/PE-A
F-SecureTrojan.TR/Injector.vnfge
DrWebTrojan.Siggen9.56514
McAfee-GW-EditionBehavesLike.Win32.Vopak.cc
EmsisoftGen:Variant.Cerbu.91704 (B)
IkarusTrojan.Win32.Injector
AviraTR/Injector.mlxlf
MAXmalware (ai score=84)
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftTrojan:Win32/Androm.RF!MTB
GridinsoftTrojan.Win32.Downloader.sa
ArcabitZum.Androm.1
AhnLab-V3Trojan/Win32.RL_Androm.R367639
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
GDataMSIL.Backdoor.ASyncRAT.9J7W34
CynetMalicious (score: 100)
McAfeeArtemis!1C97FDA2BC2D
MalwarebytesTrojan.Injector.DL.Generic
PandaTrj/CI.A
TencentWin32.Trojan.Agent.Eaxr
SentinelOneStatic AI – Suspicious PE
FortinetW32/Stealer.IO68!tr
AVGWin32:InjectorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.Androm.HyoDiLsA

How to remove Cerbu.91704?

Cerbu.91704 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment