Malware

Should I remove “JS/ExtenBro.FBook.FW”?

Malware Removal

The JS/ExtenBro.FBook.FW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What JS/ExtenBro.FBook.FW virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable UAC

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.filmgetir.com
ww1.filmgetir.com
www.kingtr.click
www.pornokan.com

How to determine JS/ExtenBro.FBook.FW?


File Info:

crc32: 419F0C2C
md5: fd1930cde63a6c7d17ef376e1a05bd27
name: FD1930CDE63A6C7D17EF376E1A05BD27.mlw
sha1: 50ba79bff25091203c4fa111f821580ca1913d11
sha256: a30e0291a679d5b7ad58b72aa1d0057b3554ee4f595a48809be4b7f53422ed40
sha512: 7894f20d74fa4325c9fbf1171b8f78fa889499944b271c7996a9645a043a446077cba98355206bd3abfbee91a75ff9e1e1f74d6c1040cf97460da828e05838d1
ssdeep: 12288:CNIQAPGsAqY9IMVYd38sJdpQH8NlY8Kf0REZ51LUEOPRnfG:vPGSY91VwNJcczq0ROVOPRnfG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Apple Inc.
FileDescription: Apple Inc. 9.1.2 Installation
FileVersion: 9.1.2
Comments:
CompanyName: Apple Inc.
Translation: 0x0409 0x04e4

JS/ExtenBro.FBook.FW also known as:

K7AntiVirusTrojan ( 004c2c031 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.42340
CynetMalicious (score: 99)
ALYacGen:Variant.Ransom.1994
CylanceUnsafe
SangforRansom.Win32.Blocker.kwsu
K7GWTrojan ( 004c2c031 )
Cybereasonmalicious.de63a6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of JS/ExtenBro.FBook.FW
APEXMalicious
AvastWin32:Downloader-VYF [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.kwsu
BitDefenderGen:Variant.Ransom.1994
NANO-AntivirusTrojan.Win32.Blocker.ezbseq
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanGen:Variant.Ransom.1994
TencentWin32.Trojan.Generic.Ednl
Ad-AwareGen:Variant.Ransom.1994
SophosMal/Generic-S
ComodoMalware@#326xyjz3hwaea
BitDefenderThetaGen:NN.ZexaF.34692.Pq3@ayBN4sai
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BPUSH.SM
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.fd1930cde63a6c7d
EmsisoftGen:Variant.Ransom.1994 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.bdkyh
WebrootW32.Rogue.Gen
AviraTR/Agent.674791
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Kilim.U
ArcabitTrojan.Ransom.D7CA
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ransom.1994
AhnLab-V3Trojan/Win32.Blocker.C742060
McAfeeArtemis!FD1930CDE63A
MAXmalware (ai score=84)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesTrojan.KBayi.FLA
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BPUSH.SM
RisingDownloader.Agent!8.B23 (RDMK:cmRtazq0/NIWCNTIt9QozJyMQkOP)
IkarusTrojan.Win32.AHK
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Downloader-VYF [Trj]
Paloaltogeneric.ml

How to remove JS/ExtenBro.FBook.FW?

JS/ExtenBro.FBook.FW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment