Malware

What is “Win32/KillMBR.NCM”?

Malware Removal

The Win32/KillMBR.NCM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/KillMBR.NCM virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Attempted to write directly to a physical drive

Related domains:

wpad.local-net

How to determine Win32/KillMBR.NCM?


File Info:

name: 9AB09AB975174A7022E7.mlw
path: /opt/CAPEv2/storage/binaries/5a7564c6cfa7e5a3614952a4ebfc44cc4807b2f8cf44cb7ba25f48db6465d79d
crc32: 242C6B17
md5: 9ab09ab975174a7022e7c6bbb0139975
sha1: 485351428634a16e99e88e9e04b0481ffd76c5cb
sha256: 5a7564c6cfa7e5a3614952a4ebfc44cc4807b2f8cf44cb7ba25f48db6465d79d
sha512: 8798c224220c6026152ba6767e51c862c500f308dfcb65da5b38cd458d818544059ad368d479c6468c4ba3fa026b015852f4cb2f817933964fa66a9400c0f0e3
ssdeep: 6144:tMbIifFS/xmZ1gXl7/3v2o7qaZ/HoBEd:+Bk5mZ1g1T/tRoBq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T136844B2178848172DCF230FA47ECB17211ADA8F0072559D716DC1BFADA641E17F36ABA
sha3_384: f5ae1740e1e3638f969e5fbbf2678e9b059e26387a3f908be21e7277489bd98eb561c0f444d5fef8be711c2d2e46aba9
ep_bytes: e9cf5b0000e950010100e9cf930400e9
timestamp: 2016-08-26 13:56:50

Version Info:

0: [No Data]

Win32/KillMBR.NCM also known as:

LionicTrojan.Win32.DiskWriter.4!c
McAfeeArtemis!9AB09AB97517
AlibabaTrojan:Win32/DiskWriter.0ce133f0
K7GWTrojan ( 0058adc71 )
K7AntiVirusTrojan ( 0058adc71 )
BitDefenderThetaGen:NN.ZexaF.34294.xKW@auR05Cbi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KillMBR.NCM
APEXMalicious
KasperskyTrojan.Win32.DiskWriter.hcu
AvastWin32:Trojan-gen
McAfee-GW-EditionArtemis
SophosMal/Generic-S
GDataWin32.Trojan.Agent.STYJLR
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R453518
TrendMicro-HouseCallTROJ_GEN.R002H0DKO21
RisingTrojan.Generic@ML.96 (RDML:14XlHWsH+U/s+aLEboyN9w)
IkarusTrojan.Win32.KillMBR
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KillMBR.NCM!tr
AVGWin32:Trojan-gen

How to remove Win32/KillMBR.NCM?

Win32/KillMBR.NCM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment