The W95/Marburg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.
Gridinsoft Anti-Malware
Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
What W95/Marburg virus can do?
- Creates RWX memory
- Unconventionial binary language: Russian
- Unconventionial language used in binary resources: Russian
- The binary likely contains encrypted or compressed data.
- Checks for the presence of known windows from debuggers and forensic tools
- Network activity detected but not expressed in API logs
- Anomalous binary characteristics
Related domains:
z.whorecord.xyz |
a.tomx.xyz |
How to determine W95/Marburg?
File Info:
crc32: 41ED19B5md5: 677714d3eeda13a0513cf4ac32cea1d1name: setup.exesha1: d4586bded8de277c1eb2ce80ad66427cf7158b89sha256: cb9baee3a67323fa5eada0495ee718b4486683f936fe645d8e396aec9454b31asha512: 370c8739bd283c2afd955ca97c049c5ae83157fa7231b2a60a6911bb8bd199e1444668a69547b00f14654649557764f9bbe167b21ae4f56af4974958b95402f8ssdeep: 24576:x/NlSjIUGBrSiZjpylwLKHrCTavksuIZiIskR0F9f98TG47fVRo8e:dNleIUGB+BU/su44X8BDodtype: PE32 executable (GUI) Intel 80386, for MS WindowsVersion Info:
LegalCopyright: (C) x41cx438x445x435x435x43dx43ax43ex432 x410x43bx435x43ax441x435x439 x412x43bx430x434x438x43cx438x440x43ex432x438x447InternalName: installerFileVersion: 1.0.0.0CompanyName: SMS-SoftwareLegalTrademarks: ChipTuningPRO InstallerComments: ProductName: ChipTuningPRO InstallerProductVersion: 1.0.0.0FileDescription: ChipTuningPRO InstallerOriginalFilename: setup.exeTranslation: 0x0419 0x04e3
W95/Marburg also known as:
Bkav | W32.AIDetectVM.malware5 |
MicroWorld-eScan | Trojan.GenericKD.34350421 |
FireEye | Trojan.GenericKD.34350421 |
McAfee | Artemis!677714D3EEDA |
VIPRE | Trojan.Win32.Generic!BT |
Arcabit | Trojan.Generic.D20C2555 |
Symantec | Trojan.Gen.2 |
TotalDefense | Win95/Marburg |
APEX | Malicious |
BitDefender | Trojan.GenericKD.34350421 |
AegisLab | Trojan.Win32.Generic.4!c |
Rising | Trojan.Zpevdo!8.F912 (CLOUD) |
Ad-Aware | Trojan.GenericKD.34350421 |
Comodo | MalCrypt.Indus!@1qrzi1 |
Sophos | W95/Marburg |
Microsoft | Trojan:Win32/Wacatac.C!ml |
GData | Trojan.GenericKD.34350421 |
ALYac | Trojan.GenericKD.34350421 |
MAX | malware (ai score=87) |
VBA32 | TScope.Trojan.Delf |
TrendMicro-HouseCall | TROJ_GEN.R002H0CHE20 |
MaxSecure | Trojan.Malware.300983.susgen |
AVG | Win32:Malware-gen |
Avast | Win32:Malware-gen |
How to remove W95/Marburg?
- Download and install GridinSoft Anti-Malware.
- Open GridinSoft Anti-Malware and perform a “Standard scan“.
- “Move to quarantine” all items.
- Open “Tools” tab – Press “Reset Browser Settings“.
- Select proper browser and options – Click “Reset”.
- Restart your computer.
Leave a Comment