Backdoor

About “Backdoor:Win32/Marduk.B” infection

Malware Removal

The Backdoor:Win32/Marduk.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Marduk.B virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Backdoor:Win32/Marduk.B?


File Info:

crc32: F774E7FD
md5: 1c3e805015d893ec132f59ab18336ed9
name: 1C3E805015D893EC132F59AB18336ED9.mlw
sha1: 9e92e34e6cfea59b0826a2c1b7c2a1cc75c74cd9
sha256: 821945dbe116f1f4c138a9da14ac4a7f1bfdf5d23e1d17c357d063377ba1489d
sha512: 35f4597b418a1a4232dff1e459e7cf9fbc0aa539aa4968029d8340a6c2be98cc0bdc352be3ef64ed2e11697cc8191b2d649bba6367a22bfd7a6474c2d29f9767
ssdeep: 12288:QaVM6ggR5xz15l92o571zmsvAYkRJ16l6xg8YWIXeAY7Y5iQqn6c:QaVM6ggR5xx5hfvVYv6lp8YWqevY5L+
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Marduk.B also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Inject.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.1223
ClamAVWin.Trojan.Agent-1844332
ALYacTrojan.GenericKD.43834115
CylanceUnsafe
ZillyaTrojan.Stealer.Win32.293
SangforTrojan.Win32.Inject.akcql
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaBackdoor:Win32/Marduk.9b660f7b
K7GWTrojan-Downloader ( 0055e3da1 )
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
SymantecTrojan.Gen.2
ESET-NOD32Win32/PSW.Stealer.NAK
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.akcql
BitDefenderTrojan.GenericKD.43834115
NANO-AntivirusTrojan.Win32.AD.ehobeq
MicroWorld-eScanTrojan.GenericKD.43834115
TencentMalware.Win32.Gencirc.10ce4860
Ad-AwareTrojan.GenericKD.43834115
SophosMal/Generic-R + Troj/Dloadr-ECT
ComodoMalware@#27w2gvh4l321x
BitDefenderThetaGen:NN.ZedlaF.34050.Gq4@aWCq13k
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_MARDUK.A
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.1c3e805015d893ec
EmsisoftTrojan.GenericKD.43834115 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.apqi
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1107660
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1D9DC34
KingsoftWin32.Troj.Agent.ac.(kcloud)
MicrosoftBackdoor:Win32/Marduk.B
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Generic.D29CDB03
ZoneAlarmTrojan.Win32.Inject.akcql
GDataTrojan.GenericKD.43834115
AhnLab-V3Malware/Win32.Generic.C2098982
McAfeeGeneric BackDoor.gw
MAXmalware (ai score=100)
VBA32Trojan.Inject
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_MARDUK.A
RisingBackdoor.Marduk!1.BF6B (CLASSIC)
YandexTrojan.GenAsa!n86y4pB4UY8
IkarusTrojan-PSW.Stealer
FortinetW32/Generic.AC.379BBC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dynamer.Hx4CuB0A

How to remove Backdoor:Win32/Marduk.B?

Backdoor:Win32/Marduk.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment