Trojan

Trojan.MBRModifier removal tips

Malware Removal

The Trojan.MBRModifier is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MBRModifier virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.MBRModifier?


File Info:

name: 9C287F675743D0802B4F.mlw
path: /opt/CAPEv2/storage/binaries/035d640dd284be06993a63bef62ed3b7744bf2f9e5a42120d6324035de0fa5db
crc32: 73D5C172
md5: 9c287f675743d0802b4f040004badc44
sha1: 36662f2e51473a687eaa0b1596624ecff17613fb
sha256: 035d640dd284be06993a63bef62ed3b7744bf2f9e5a42120d6324035de0fa5db
sha512: 243613561d31cbe73fcf58e2aeb9294fb7c6d211b834e31cadbb4a0ea05836fcd48701127a9450947b1568cee7abb29d31aa1ce1f4406ac908e1bfbe9bfd2cd6
ssdeep: 24576:8Rby8aCSH7y2M9V6elEvpHi/TT//BMGwpLV3wrscmlg:eby5HK9V6fvwLXIL5wrsc3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE3512E2CF4043F7E9861B3F94A3373A6778AB7137634B43255412626CE27E52D26394
sha3_384: b4258a0084bc0aed45860f54fc1ad69ffd21d13b84a1ae1e78403dfabd960a252ed8a54810eb7486dbf2c8be198a0e36
ep_bytes: 60e847fbffff6183ec045053b8a0c55b
timestamp: 2021-10-06 10:53:33

Version Info:

0: [No Data]

Trojan.MBRModifier also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!9C287F675743
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 00543a811 )
AlibabaTrojan:Win32/Occamy.ab7cb3db
K7GWTrojan ( 00543a811 )
Cybereasonmalicious.75743d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Virbox.C suspicious
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.787864
MicroWorld-eScanGen:Variant.Razy.787864
AvastWin32:Evo-gen [Susp]
RisingTrojan.Generic@ML.88 (RDML:34wFxhsrJt1zvqjGgZ87fg)
Ad-AwareGen:Variant.Razy.787864
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.MulDrop18.42594
TrendMicroTROJ_GEN.R002C0DJ721
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.9c287f675743d080
EmsisoftGen:Variant.Razy.787864 (B)
IkarusPUA.Virbox
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Razy.DC0598
GDataWin32.Application.PUPStudio.A
AhnLab-V3Trojan/Win.Generic.R426881
Acronissuspicious
VBA32BScope.Trojan.Kraplick.vck
ALYacGen:Variant.Razy.787864
MAXmalware (ai score=89)
MalwarebytesTrojan.MBRModifier
TrendMicro-HouseCallTROJ_GEN.R002C0DJ721
TencentWin32.Trojan.Generic.Htvs
YandexTrojan.Agent!UTOysofNFjk
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Application
BitDefenderThetaGen:NN.ZexaF.34294.cH3@aK3p2Aeb
AVGWin32:Evo-gen [Susp]
PandaTrj/GdSda.A
MaxSecureDropper.Dinwod.frindll

How to remove Trojan.MBRModifier?

Trojan.MBRModifier removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment