Malware

Ser.Cerbu.3775 removal

Malware Removal

The Ser.Cerbu.3775 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Cerbu.3775 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

How to determine Ser.Cerbu.3775?


File Info:

name: 7D897988A86752335BB7.mlw
path: /opt/CAPEv2/storage/binaries/c2f3332703fe5e81da94c8b8ff554c46bd1da750868216a6f8d35905c268a0b6
crc32: 99DA0150
md5: 7d897988a86752335bb7d85218e2e468
sha1: 76a71e7bcb670a6581acbb5db7430b6075717b8f
sha256: c2f3332703fe5e81da94c8b8ff554c46bd1da750868216a6f8d35905c268a0b6
sha512: 6fa0b9385e0c7f345dd6d28d78ffc8ee0f9d4035cb321bf759f879949b53fbb27f06163244257b609dab10b6d0f267ea29994fc6f1e53f2dc9e7f30da68e3762
ssdeep: 98304:IlV8s0OunXSXzWouWYDbqSdJqTScJyxg5+OEuIP8RTVe2Z0I4rt1gpo:AnunyCouWYfq8BccOEuISI/IXu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152263381DA918C7FD0FD3EB0FA15118CBD033B519D35EA670A5EE65EC427A21939CAC8
sha3_384: 5548b2e8a13e5086d03461f0d72139054c22ce2a5fd8e9bb360d08ac9fcde0cdf2c91991544099a24d61f519daa1f434
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Lector Vt. Ltd.
FileDescription: Professional Recovery - Demo Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Ser.Cerbu.3775 also known as:

MicroWorld-eScanGen:Variant.Ser.Cerbu.3775
FireEyeGen:Variant.Ser.Cerbu.3775
ALYacGen:Variant.Ser.Cerbu.3775
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Ekstak.b673b40f
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
CyrenW32/Agent.DZN.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.aldcs
BitDefenderGen:Variant.Ser.Cerbu.3775
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Ser.Cerbu.3775
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WA422
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
EmsisoftGen:Variant.Ser.Cerbu.3775 (B)
GDataWin32.Backdoor.Bodelph.2JH7SF
JiangminTrojan.Ekstak.buza
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Ser.Cerbu.DEBF
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!7D897988A867
MAXmalware (ai score=83)
VBA32Trojan.Ekstak
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R002C0WA422
TencentWin32.Trojan.Ekstak.Akpl
IkarusTrojan-Dropper.Win32.Agent
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Ser.Cerbu.3775?

Ser.Cerbu.3775 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment