Trojan

About “Trojan:Win32/ExtenBro!MSR” infection

Malware Removal

The Trojan:Win32/ExtenBro!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/ExtenBro!MSR virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:Win32/ExtenBro!MSR?


File Info:

name: 21411DEC44CB950FF7C3.mlw
path: /opt/CAPEv2/storage/binaries/b37761715d5a2405a3fa75abccaf6bb15b7298673aaad91a158725be3c518a87
crc32: BBD8FC0F
md5: 21411dec44cb950ff7c33854949cf6d9
sha1: c672a8f4a39c35f0f12c8fdc5e1f8a34c7236d7a
sha256: b37761715d5a2405a3fa75abccaf6bb15b7298673aaad91a158725be3c518a87
sha512: fc6e634d91f296013e78d46f62a1e3b36a6bf704105e96ba21ffd8da7f6e167135c9740c28cad8f1bc50da98ba992bc87ab02b8129cda740cd24e82d255d528f
ssdeep: 6144:bbeYl5cwyARM4eeWXiKjQjHITs7TFSlf+BhhTR5U3Hje6u8bQn9JzHrLiOWR3:+Yl5cwyAGs7T0f+BhhTR5UUxHSOo3
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T144943F49E78D486FCCFF45F838185D847B329F8AD4819186ADECF7A94830936BE52385
sha3_384: a3f956161b76a27bef41ab31c79e24c76cd450a58818f8245fdf481d96478d5826cab53980a9be80d1638d7f919d23d8
ep_bytes: ff250020400000000000000000000000
timestamp: 2045-02-26 01:44:41

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Google
FileDescription: Google Software Update
FileVersion: 1.0.0.0
InternalName: Google Software Update.exe
LegalCopyright: Copyright © 2019 Google Inc
LegalTrademarks: Google Inc
OriginalFilename: Google Software Update.exe
ProductName: Google Software Update
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:Win32/ExtenBro!MSR also known as:

BkavW32.AIDetectNet.01
LionicRiskware.Win32.Bulz.1!c
CynetMalicious (score: 100)
McAfeeRDN/Generic.dx
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.24525
SangforTrojan.Msil.Delshad.Vfu6
K7AntiVirusTrojan ( 005941fb1 )
AlibabaTrojan:MSIL/DelShad.262ddffa
K7GWTrojan ( 005941fb1 )
Cybereasonmalicious.c44cb9
CyrenW32/ABRisk.XDZZ-1135
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32MSIL/Filecoder.HavanaCrypt.A
TrendMicro-HouseCallRansom.MSIL.HAVANACRYPT.THFACBB
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.DelShad.gen
BitDefenderIL:Trojan.MSILMamut.5096
NANO-AntivirusTrojan.Win32.DelShad.jqclvk
MicroWorld-eScanIL:Trojan.MSILMamut.5096
AvastWin32:Malware-gen
TencentMsil.Trojan.Delshad.Hnun
Ad-AwareIL:Trojan.MSILMamut.5096
EmsisoftIL:Trojan.MSILMamut.5096 (B)
ComodoMalware@#1yuc1tf1nw6z7
DrWebTrojan.DownLoader44.64115
VIPREIL:Trojan.MSILMamut.5096
TrendMicroRansom.MSIL.HAVANACRYPT.THFACBB
McAfee-GW-EditionTrojan-filecoder.b
SentinelOneStatic AI – Suspicious PE
FireEyeIL:Trojan.MSILMamut.5096
APEXMalicious
GDataIL:Trojan.MSILMamut.5096
JiangminTrojan.MSIL.anays
WebrootW32.Ransom.Gen
AviraTR/Ransom.dhthr
Antiy-AVLTrojan/Generic.ASMalwS.6F12
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitIL:Trojan.MSILMamut.D13E8
MicrosoftTrojan:Win32/ExtenBro!MSR
AhnLab-V3Trojan/Win.Generic.C5168759
ALYacTrojan.Ransom.Filecoder
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt.MSIL
RisingRansom.Agent!8.6B7 (CLOUD)
IkarusTrojan-Ransom.HavanaCrypt
MaxSecureTrojan.Malware.74133646.susgen
FortinetMSIL/Filecoder.ARP!tr.ransom
AVGWin32:Malware-gen
PandaTrj/RansomGen.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/ExtenBro!MSR?

Trojan:Win32/ExtenBro!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment