Malware

Should I remove “Ser.Cerbu.753”?

Malware Removal

The Ser.Cerbu.753 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Cerbu.753 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Attempts to create or modify a Browser Helper Object
  • Creates a copy of itself
  • Deletes executed files from disk
  • Created a service that was not started

How to determine Ser.Cerbu.753?


File Info:

name: 41AA7004A0EFF0145FC9.mlw
path: /opt/CAPEv2/storage/binaries/65b8b3994f4ba8c4aa960da9bf87e2d0d6517923ec3a456314f7d5b266b8a0f1
crc32: B614B6B8
md5: 41aa7004a0eff0145fc9f257d59409d6
sha1: e27208bd9b8102e9c63bea5b3301dbbaf6f4170a
sha256: 65b8b3994f4ba8c4aa960da9bf87e2d0d6517923ec3a456314f7d5b266b8a0f1
sha512: 99d4929656d37f2ed4fd99549961fc3b112ad824739e99182a66581cc863ca2fc48eb2f3db1a6a2841a71d3d6a6998e934f0d83544af52ade4d5b23fc5801f0f
ssdeep: 6144:Ct9JU9XS8GMCICzADJLHVbCyfqXozHpwIH4ymoSBWrK75V2e2Ma+es/nOy03rpoS:JDSxzAN3aIFSBKKtsa07RlxUU
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D9B48D61FF65C5F1D491917E1C9BB60606B6EBD10B1652CF26A83A2FBDB43C20E322D1
sha3_384: 4e4edd9ed763833ddfb5fca3b3c97cfd2bfde9b0404411734d8ef8b48a7620b2c571dd0e9020df57895956bf78c3b2b8
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2010-07-21 15:01:14

Version Info:

Comments:
CompanyName: 迅雷支持模块
FileDescription: www.xunlei.com
FileVersion: 5, 0, 0, 1
InternalName: Thunder
LegalCopyright: Copyright 2009
LegalTrademarks:
OLESelfRegister:
OriginalFilename: Thunder.DLL
PrivateBuild:
ProductName: Thunder Module
ProductVersion: 5, 0, 0, 1
SpecialBuild:
Translation: 0x0409 0x04b0

Ser.Cerbu.753 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.21214
MicroWorld-eScanGen:Variant.Ser.Cerbu.753
FireEyeGeneric.mg.41aa7004a0eff014
SkyhighBehavesLike.Win32.Dropper.gh
ALYacGen:Variant.Ser.Cerbu.753
Cylanceunsafe
ZillyaDownloader.BHO.Win32.1690
CynetMalicious (score: 100)
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0017c68f1 )
K7AntiVirusTrojan ( 0017c68f1 )
BitDefenderThetaGen:NN.ZedlaF.36802.Eu@@aqE2!8fb
VirITTrojan.Win32.Generic.LGL
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Koutodoor.GU
APEXMalicious
ClamAVWin.Malware.Scar-6746057-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Cerbu.753
NANO-AntivirusTrojan.Win32.BT.etkua
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastWin32:Agent-ACUA [Drp]
RisingTrojan.Meredrop!8.6CD (TFE:5:jU9QjL1WI8G)
EmsisoftGen:Variant.Ser.Cerbu.753 (B)
F-SecureTrojan.TR/Rogue.4712135.14
VIPREGen:Variant.Ser.Cerbu.753
TrendMicroTROJ_DLOADR.SMO1
SophosTroj/Mdrop-JSK
IkarusTrojan-Downloader.Win32.BHO
JiangminTrojan/Generic.aoix
WebrootW32.Downloader.Gen
VaristW32/Agent.EM.gen!Eldorado
AviraTR/Rogue.4712135.14
Antiy-AVLTrojan[Downloader]/Win32.BHO
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Multiverze
XcitiumTrojWare.Win32.TrojanDownloader.Agent.BT_dll0@1d9fhs
ArcabitTrojan.Ser.Cerbu.753
ViRobotTrojan.Win32.A.Scar.28672.Q
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ser.Cerbu.753
GoogleDetected
AhnLab-V3Trojan/Win32.BHO.R2876
McAfeeDownloader-BT.a.dll
MAXmalware (ai score=88)
VBA32Trojan.Ditertag
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DLOADR.SMO1
TencentTrojan.Win32.Koutodoor.xa
YandexTrojan.GenAsa!KQnQdVQ9Y1E
SentinelOneStatic AI – Suspicious PE
FortinetW32/BHO.OAT!tr
AVGWin32:Agent-ACUA [Drp]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Ser.Cerbu.753?

Ser.Cerbu.753 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment