Malware

Cerbu.93221 (B) removal guide

Malware Removal

The Cerbu.93221 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.93221 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings

How to determine Cerbu.93221 (B)?


File Info:

crc32: 796C44EB
md5: 937b3a38de78efb77eb6d8fb4c741051
name: 937B3A38DE78EFB77EB6D8FB4C741051.mlw
sha1: 305eba6b746ff40758172f35308a5174067976f1
sha256: 752abe1050403b95676de500b60db8b36e26f02e4b24eb84ae9f4daf6d03b957
sha512: d46334bfc8ece1dc1c872eb92f449e6b38f4514dfa425c2cf5dbd25b14ec9dba81441526a6ef4046d57d47cde76b1da487f768672a500d56160d62905b8e2b05
ssdeep: 98304:ZX6Zrjl6Q0hFPuXKkHgkxgKTPn8KvoKGqLGlN0duHG+kl0/mfp:x6ZrjeF2Fgq88sIvduHG+kK/mfp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Jet Cleaning Technologies
Comments: This installation was built with Inno Setup.
ProductName: JCleaner
ProductVersion: 1.5
FileDescription: JCleaner Setup
Translation: 0x0000 0x04b0

Cerbu.93221 (B) also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.PWS.Siggen2.62935
CynetMalicious (score: 85)
ALYacGen:Variant.Cerbu.93221
CyrenW32/MSIL_Kryptik.AFN.gen!Eldorado
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Coins.gen
BitDefenderTrojan.GenericKD.45932141
NANO-AntivirusTrojan.Win32.Coins.iplqek
MicroWorld-eScanTrojan.GenericKD.45932141
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.rc
FireEyeGen:Variant.Cerbu.93221
EmsisoftGen:Variant.Cerbu.93221 (B)
JiangminTrojan.PSW.Kpot.bi
AviraTR/PSW.Coins.qmfuu
MicrosoftTrojan:Win32/ClipBanker.MR!MTB
GridinsoftTrojan.Win32.Agent.dd!n
ArcabitTrojan.Cerbu.D16C25
ZoneAlarmHEUR:Trojan-PSW.MSIL.Coins.gen
GDataGen:Variant.Cerbu.93221
McAfeeArtemis!937B3A38DE78
MAXmalware (ai score=80)
MalwarebytesTrojan.Dropper
RisingDownloader.Agent!8.B23 (CLOUD)
IkarusTrojan.Win32.VB
FortinetW32/Coins.MZFXFPE!tr.pws
AVGWin32:CoinminerX-gen [Trj]
Qihoo-360HEUR/QVM06.1.0967.Malware.Gen

How to remove Cerbu.93221 (B)?

Cerbu.93221 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment