Malware

BrowserModifier:Win32/Troboxi.A malicious file

Malware Removal

The BrowserModifier:Win32/Troboxi.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BrowserModifier:Win32/Troboxi.A virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to modify Internet Explorer’s start page
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com

How to determine BrowserModifier:Win32/Troboxi.A?


File Info:

crc32: 058D2D38
md5: d6ef21e0379386ac9eb6b111ccd5fd0e
name: D6EF21E0379386AC9EB6B111CCD5FD0E.mlw
sha1: 6f623fca09bf9de14f064a27b073e704396aa7e1
sha256: 1dc93e74f784991dd2cf230124ea966171511d4d5966881efea4fdbc552fb086
sha512: f8d79de4a7a6b30588a389ed95eab54314141786102f4a4292b355a26b15e13bd029689148e31f27219a1dceb5e8791160573141f8fbd2d9f4fc300fc45605c6
ssdeep: 3072:04OCpkuGytZ1D4/T62wW7pfDKWcVG8ezjwSh9JT87r5Fsj6kpWi:04OfaZC/T65G4SNGW
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

BrowserModifier:Win32/Troboxi.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 003ac30f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.StartPage.47909
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.89394
CylanceUnsafe
ZillyaTrojan.Injector.Win32.128273
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 003ac30f1 )
Cybereasonmalicious.037938
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.TRS
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.89394
NANO-AntivirusTrojan.Win32.StartPage.vruld
MicroWorld-eScanGen:Variant.Barys.89394
TencentWin32.Trojan.Startpage.Wtxn
Ad-AwareGen:Variant.Barys.89394
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.EBA2D6171F
VIPRETrojan.Win32.Zbot.agf (v)
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
FireEyeGeneric.mg.d6ef21e0379386ac
EmsisoftGen:Variant.Barys.89394 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/StartPage.lvr
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_89%
Antiy-AVLTrojan/Generic.ASMalwS.113409
MicrosoftBrowserModifier:Win32/Troboxi.A
ArcabitTrojan.Barys.D15D32
GDataGen:Variant.Barys.89394
Acronissuspicious
McAfeePWS-Zbot.gen.agf
MAXmalware (ai score=99)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.1921711404
PandaGeneric Malware
RisingMalware.Heuristic!ET#97% (RDMK:cmRtazrmHEkag5TPamjt9J+qreGT)
YandexTrojan.GenAsa!XD4YXqHVPNY
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ZBot.EKC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove BrowserModifier:Win32/Troboxi.A?

BrowserModifier:Win32/Troboxi.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment