Malware

Win32:MBRlock-EW [Trj] information

Malware Removal

The Win32:MBRlock-EW [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:MBRlock-EW [Trj] virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Likely installs a bootkit via raw harddisk modifications
  • Deletes its original binary from disk
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32:MBRlock-EW [Trj]?


File Info:

crc32: D5680601
md5: d9c53559e345fdd28c0888ed700058ab
name: D9C53559E345FDD28C0888ED700058AB.mlw
sha1: 8932d3ca20a32aa7b0e435656d02edb5cf12cf29
sha256: 4171056d7c9c9414dec2670318c4c7e29cfc839da4042609a8e91e1c171882b3
sha512: 080715ff93827319e5288ef4a9cbff46a0682256c57ebe43b377f6b2ac8f248b6ab9c9c4c5760fe20f3caf10552d54376e39cef35c1d53c263d5c54732f0108f
ssdeep: 3072:7AaI3MBeLjojw2r0r4dkz/fiFxWvFwh9r6xQ09OEfMN33Am4g9Mcinp+:EaIcBcGT4/CJM03Au9Up+
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32:MBRlock-EW [Trj] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004bcce41 )
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.6
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur3.LPT.mmW@aaM!6Maib
CylanceUnsafe
ZillyaTrojan.MBRlock.Win32.432
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Genasom.736eefa7
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.9e345f
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/MBRlock.D
APEXMalicious
AvastWin32:MBRlock-EW [Trj]
KasperskyHEUR:Trojan-Ransom.Win32.Foreign.gen
BitDefenderGen:Trojan.Heur3.LPT.mmW@aaM!6Maib
NANO-AntivirusTrojan.Win32.Mbro.blwjrm
MicroWorld-eScanGen:Trojan.Heur3.LPT.mmW@aaM!6Maib
TencentWin32.Trojan.Generic.Wugz
Ad-AwareGen:Trojan.Heur3.LPT.mmW@aaM!6Maib
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.7254793521
VIPREVirtool.Win32.DelfInject.cpn (v)
McAfee-GW-EditionPolyPatch-UPX
FireEyeGeneric.mg.d9c53559e345fdd2
EmsisoftGen:Trojan.Heur3.LPT.mmW@aaM!6Maib (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/MBro.egg
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.486AA0
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Genasom.JJ
ArcabitTrojan.Heur3.LPT.E8B202
AegisLabTrojan.Win32.Generic.li1F
GDataGen:Trojan.Heur3.LPT.mmW@aaM!6Maib
AhnLab-V3Trojan/Win32.Ransom.R59315
Acronissuspicious
McAfeePolyPatch-UPX
MAXmalware (ai score=100)
VBA32Hoax.MBro
PandaGeneric Malware
YandexTrojan.GenAsa!tX2xMS0Puwk
IkarusTrojan-Ransom.Mbro
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.fam!tr
AVGWin32:MBRlock-EW [Trj]
Qihoo-360Win32/Ransom.Genasom.HgIASVsA

How to remove Win32:MBRlock-EW [Trj]?

Win32:MBRlock-EW [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment