Home Malware Programs Malware KillMBR-FBIA

KillMBR-FBIA

Posted: March 22, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 61
First Seen: March 22, 2013
Last Seen: October 27, 2022
OS(es) Affected: Windows

KillMBR-FBIA is a malware threat that is a component of an Internet malware attack targeting South Korean banks and media companies. KillMBR-FBIA wipes out the master boot records on the hard drives of the affected computer, overwriting the MBR with one of the strings 'PRINCPES', 'PR!NCPES' and 'HASTATI'. KillMBR-FBIA also overwrites random parts of the file system with the same strings, rendering several files unrecoverable. So even if the MBR is recovered, the files on disk will be compromised too. After that, the computer system is pressed to reboot via the certain command. That action makes the computers to be unable to start because the MBR is affected. Before overwriting the MBR, KillMBR-FBIA attempts to kill the main processes of two Korean anti-virus software products, Ahnlab and Hauri. The main aim of KillMBR-FBIA is to make the hacked computers unusable.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



pr1.tmp File name: pr1.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
APCRunCmd.DRP File name: APCRunCmd.DRP
Mime Type: unknown/DRP
Group: Malware file
ApcRunCmd.exe File name: ApcRunCmd.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
mb_join.exe File name: mb_join.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
OthDown.exe File name: OthDown.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
E4F66C3CD27B97649976F6F0DAAD9032.bin File name: E4F66C3CD27B97649976F6F0DAAD9032.bin
File type: Binary File
Mime Type: unknown/bin
Group: Malware file
jar_cache1221312510715123682.tmp File name: jar_cache1221312510715123682.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file

Additional Information

The following URL's were detected:
onelastoffer.com
Loading...