Categories: Virus

Virus.Bundler.MPRESS removal

The Virus.Bundler.MPRESS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Bundler.MPRESS virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Virus.Bundler.MPRESS?


File Info:

name: 3CAEB6D5D31125CE4AFD.mlwpath: /opt/CAPEv2/storage/binaries/ce06484de9df7e849f31e1affa1188224e33dd489d51ccedc99bef555e15da86crc32: 63954B95md5: 3caeb6d5d31125ce4afd9999f8380c90sha1: d9a61365a53c47ff8adf61a50db9f3f93db4f2b7sha256: ce06484de9df7e849f31e1affa1188224e33dd489d51ccedc99bef555e15da86sha512: 3b606d1bdc5e326b2bb3cecb35949f3909f0ca917d9f2a319117789c450fc531445e5a41ee138035151f41adab4a955c44f0e56c15ee844a4a5204a8c8bb80cfssdeep: 6144:LlNgw6P+TKzJOEYLBL1wr7NuS7tzKPcl5VM:jhnTkYVSrJuOeAMtype: PE32 executable (console) Intel 80386, for MS Windowstlsh: T1EC24135BF9AFF9B4FB5132328460F885556B1232D2D6020B7D83175EBEC06621EF93A1sha3_384: 6d8d1f7e4e6c5058173ea2ad74b8635efa65df9ce8a968105f4c59a7d56169c4ced399e2bb2f313e4bb49fe54be0e290ep_bytes: 60e80000000058055a0b00008b3003f0timestamp: 2011-03-25 13:17:51

Version Info:

0: [No Data]

Virus.Bundler.MPRESS also known as:

Bkav W32.AIDetect.malware2
tehtris Generic.Malware
MicroWorld-eScan Dropped:Trojan.GenericKD.36248848
FireEye Generic.mg.3caeb6d5d31125ce
ALYac Dropped:Trojan.GenericKD.36248848
Cylance Unsafe
Sangfor Suspicious.Win32.Save.a
K7GW Trojan ( 00577de81 )
K7AntiVirus Trojan ( 005768dd1 )
Cyren W32/Agent.DYZ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of BAT/Agent.NAS
APEX Malicious
ClamAV Win.Malware.Redcap-9828937-0
Kaspersky Trojan.BAT.Agent.bbn
BitDefender Dropped:Trojan.GenericKD.36248848
Avast Script:SNH-gen [Trj]
Tencent Malware.Win32.Gencirc.11ed8ef0
Ad-Aware Dropped:Trojan.GenericKD.36248848
Emsisoft Dropped:Trojan.GenericKD.36248848 (B)
DrWeb Trojan.Siggen12.42974
TrendMicro TROJ_GEN.R002C0DGO21
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
Sophos ML/PE-A
Ikarus Virus.BAT.Agent
GData Dropped:Trojan.GenericKD.36248848
Jiangmin Trojan.BAT.ame
Avira TR/Redcap.osjdd
Antiy-AVL Trojan/Generic.ASMalwS.1DDC121
Arcabit Trojan.Generic.D2291D10
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Tnega.R449412
Acronis suspicious
McAfee GenericRXSE-JY!3CAEB6D5D311
MAX malware (ai score=83)
VBA32 Trojan.BAT.Agent
Malwarebytes Virus.Bundler.MPRESS
TrendMicro-HouseCall TROJ_GEN.R002C0DGO21
Rising Dropper.Agent!1.D197 (RDMK:cmRtazo058EafQEdOZ1sRXXDIZwo)
SentinelOne Static AI – Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Agent.F840!tr
BitDefenderTheta Gen:NN.ZexaF.34606.Ry0@aSfE0Qb
AVG Script:SNH-gen [Trj]
Cybereason malicious.5d3112

How to remove Virus.Bundler.MPRESS?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Trojan-Dropper.Win32.Agent.tgljob malicious file

The Trojan-Dropper.Win32.Agent.tgljob is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

Ransom:MSIL/Hibotibo.AA!MTB information

The Ransom:MSIL/Hibotibo.AA!MTB is considered dangerous by lots of security experts. When this infection is active,…

58 mins ago

Trojan-Dropper.Win32.Agent.tgbcwu removal guide

The Trojan-Dropper.Win32.Agent.tgbcwu is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Worm.Win32.Vobfus.axhs removal guide

The Worm.Win32.Vobfus.axhs is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan.Dropper.AAAM (B) (file analysis)

The Trojan.Dropper.AAAM (B) is considered dangerous by lots of security experts. When this infection is…

1 hour ago

Zusy.546276 (B) malicious file

The Zusy.546276 (B) is considered dangerous by lots of security experts. When this infection is…

1 hour ago