Threat Database Trojans Trojan.KillMBR.AT

Trojan.KillMBR.AT

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: June 14, 2024
Last Seen: January 31, 2026
OS(es) Affected: Windows

The detection of Trojan.KillMBR.AT indicates that your system has been compromised by a type of malicious software known as a Trojan. This type of threat is designed to deceive users by disguising itself as legitimate software, but in reality, it can cause significant harm to your computer and data. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is Trojan.KillMBR.AT?

Trojan.KillMBR.AT is a type of Trojan horse malware that can infect your computer without your knowledge or consent. The name "Trojan" refers to the method of infection, where the malware disguises itself as legitimate software to gain access to your system. The ".KillMBR.AT" part of the name suggests that this malware may be designed to target the Master Boot Record (MBR) of your computer, which is a critical component of your system's boot process.

How Trojan.KillMBR.AT Operates

Once Trojan.KillMBR.AT infects your computer, it can operate in various ways, depending on its intended purpose. Some common activities of Trojan malware include stealing sensitive information, such as login credentials or financial data, installing additional malware, or providing unauthorized access to your system. Trojan.KillMBR.AT may also attempt to disable security software or modify system settings to maintain its presence on your computer.

Symptoms of Infection

The symptoms of a Trojan.KillMBR.AT infection can vary, but common signs include slow system performance, unexpected crashes, or unusual network activity. You may also notice unfamiliar programs or icons on your desktop, or receive unexpected pop-ups or alerts. In some cases, your antivirus software may detect and alert you to the presence of the malware.

How to Remove Trojan.KillMBR.AT

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all instances of Trojan.KillMBR.AT.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.KillMBR.AT from your computer requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above, you can help ensure that your system is clean and secure. Remember to always be cautious when downloading software or clicking on links from unknown sources, as these are common ways that Trojans and other malware can infect your computer. Regularly updating your operating system, browser, and security software can also help prevent future infections. If you are unsure about any aspect of the removal process, consider seeking the help of a professional computer security expert.

Analysis Report

General information

Family Name: Trojan.KillMBR.AT
Signature status: No Signature

Known Samples

MD5: 2706679e636324d50eeb084ac93c13cf
SHA1: 3709fbf5cfda461325d202eb3df27d3e754720fb
SHA256: ECC51C8B8B8F6C8D197DAB33BFB811331F9DC8ED2EEFFBD86C92C9B72E6BE1CD
File Size: 105.47 KB, 105472 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • GetConsoleWindow
  • No Version Info
  • x86

Block Information

Total Blocks: 553
Potentially Malicious Blocks: 1
Whitelisted Blocks: 547
Unknown Blocks: 5

Visual Map

0 0 0 0 ? ? ? x 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 3 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 2 0 0 0 0 1 0 0 2 0 1 0 0 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 1 2 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AN
  • Agent.ANH
  • Redline.CE
  • Trojan.Agent.Gen.AHM
  • Trojan.Kryptik.Gen.AKX
Show More
  • Trojan.Kryptik.Gen.BXL

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\downloads\temp.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation

Trending

Most Viewed

Loading...