Trojan

Trojan.Sunburst.D removal tips

Malware Removal

The Trojan.Sunburst.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Sunburst.D virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Sunburst.D?


File Info:

crc32: 464B28B8
md5: f6d07f3d81dcea99b27462d100414917
name: F6D07F3D81DCEA99B27462D100414917.mlw
sha1: 395da6d4f3c890295f7584132ea73d759bd9d094
sha256: 0f5d7e6dfdd62c83eb096ba193b5ae394001bac036745495674156ead6557589
sha512: 567eede134f574cf0b4f4db75153a9039b87497cfb4078461ffb276da6e9483021c114fb04f15bec2af6daddb1a9808b84887fa742b312d415621200dad9672c
ssdeep: 12288:rx7m/z9aEBzvnvLtYAi6uLlYQ69BBpXvF1tjpH7BKi+0A8vcaIo2/:4aEBTvRBi6uL6dXvDtjpH9+0A8vcaIoC
type: PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 1999-2020 SolarWinds Worldwide, LLC. All Rights Reserved.
Assembly Version: 2019.4.5200.9078
InternalName: SolarWinds.Orion.Core.BusinessLayer.dll
FileVersion: 2019.4.5200.9078
CompanyName: SolarWinds Worldwide, LLC.
LegalTrademarks:
Comments:
ProductName: SolarWinds.Orion.Core.BusinessLayer
ProductVersion: 2019.4.5200.9078
FileDescription: SolarWinds.Orion.Core.BusinessLayer
OriginalFilename: SolarWinds.Orion.Core.BusinessLayer.dll

Trojan.Sunburst.D also known as:

BkavW32.APT159TTc.Worm
MicroWorld-eScanTrojan.Sunburst.D
CAT-QuickHealBackdoor.Sunburst.S17554866
ALYacTrojan.MSIL.SunBurst
MalwarebytesBackdoor.Sunburst
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.SunBurst.trD4
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Sunburst.D
K7GWTrojan ( 00574b2b1 )
K7AntiVirusTrojan ( 00574b2b1 )
CyrenW32/MSIL_SunBurst.A.gen!Eldorado
SymantecBackdoor.Sunburst!gen1
ESET-NOD32a variant of MSIL/SunBurst.A
Paloaltogeneric.ml
ClamAVWin.Countermeasure.Sunburst-9809152-0
KasperskyHEUR:Backdoor.MSIL.SunBurst.gen
AlibabaBackdoor:MSIL/SunBurst.36b897ea
ViRobotBackdoor.Win32.S.SunBurst.1011032
RisingBackdoor.SunBurst/APT#APT29!1.D029 (CLASSIC)
Ad-AwareTrojan.Sunburst.D
SophosMal/Sunburst-A
ComodoMalware@#3clwfh0bqny1k
F-SecureTrojan:W32/Sunburst.F
DrWebBackDoor.SiggenNET.14
ZillyaBackdoor.Sunburst.Win32.2
TrendMicroTROJ_GEN.R002C0DLH20
McAfee-GW-EditionTrojan-Sunburst!F6D07F3D81DC
FireEyeTrojan.Sunburst.D
EmsisoftTrojan.Win32.Sunburst (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Redcap.ktkyj
KingsoftWin32.Hack.Undef.(kcloud)
ArcabitTrojan.Sunburst.D
ZoneAlarmHEUR:Backdoor.MSIL.SunBurst.gen
GDataTrojan.Sunburst.D
CynetMalicious (score: 85)
AhnLab-V3Backdoor/Win32.SunBurst.R357806
McAfeeTrojan-Sunburst!F6D07F3D81DC
TACHYONBackdoor/W32.DN-SunBurst.1011032
VBA32TScope.Trojan.MSIL
PandaTrj/Solorigate.A
TrendMicro-HouseCallTROJ_GEN.R002C0DLH20
MAXmalware (ai score=83)
FortinetW32/Sunburst.A!tr
AVGMSIL:SunBurst-B [Bd]
AvastMSIL:SunBurst-B [Bd]

How to remove Trojan.Sunburst.D?

Trojan.Sunburst.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment