Home Malware Programs Trojans Trojan:Win32/Dembr.A

Trojan:Win32/Dembr.A

Posted: March 27, 2013

Threat Metric

Ranking: 13,272
Threat Level: 9/10
Infected PCs: 3,747
First Seen: March 27, 2013
Last Seen: March 9, 2025
OS(es) Affected: Windows

Trojan:Win32/Dembr.A is a Trojan that deletes the Master Boot Record (MBR), making the affected computer unusable. Trojan:Win32/Dembr.A includes a code to assure that it only runs after 14:00, on March 20, any given year. Trojan:Win32/Dembr.A may make lasting changes to the infected computer that will not be restored by detecting and removing this malware threat. Therefore, PC users will need to reinstall Windows, and restore the targeted computer from backup. Once installed, Trojan:Win32/Dembr.A will block victimized computer users from starting the PC. Trojan:Win32/Dembr.A blocks Ahnlab and Hauri anti-virus software if it finds either on the hacked computer system. Trojan:Win32/Dembr.At then makes changes to the Master Boot Record (MBR) so that, if the PC user attempts to restart the computer, it will not start. Trojan:Win32/Dembr.A attempts to avoid detection and removal by injecting a code into the legitimate Windows process 'svchost.exe'.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



update.ex File name: update.ex
Mime Type: unknown/ex
Group: Malware file
schsvcsc.dll File name: schsvcsc.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
schsvcsc.exe File name: schsvcsc.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...