Malware

About “Troj/DwnLdr-MDK” infection

Malware Removal

The Troj/DwnLdr-MDK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DwnLdr-MDK virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Troj/DwnLdr-MDK?


File Info:

name: A920F5D60E37CFD09A9A.mlw
path: /opt/CAPEv2/storage/binaries/5ff7a8805d78d4d901358c025808e8abe796882fdc45eead92ea57ab0c0b792b
crc32: C5B04761
md5: a920f5d60e37cfd09a9a90e3d87ff993
sha1: ac68708b47f2b7dafa9081b2fd1a861506bdf0d8
sha256: 5ff7a8805d78d4d901358c025808e8abe796882fdc45eead92ea57ab0c0b792b
sha512: aabd0e4152111d63baa45796ef8fc8f21303ba98e8eac108fb22cdb761378ee0b2af5f6d019145a27b6fc0a9926dc6eae5eaf0d54243d6ad778b2a6604943ed0
ssdeep: 384:KrxUgfgQBb2cP63y4byzLeReRFnpaud5ZGl02EzBrh5z9jicVDS+UJJTJZg:ehD2cS3QiI1ZGl02EzBTz93cpT/g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10CF2AE0E1E9B4963F1828974E3E64AD69FFDAC1379EA783FCF940005049119C94E2EF6
sha3_384: ce8c828db2cbd4020588ff2f9d94dd3449537686bda4d1afdc9d2a50732d33cff2ff629490deeac5eab0dc5ce6fd8305
ep_bytes: 558bec81ec380300005356576a4033db
timestamp: 2010-08-09 01:44:42

Version Info:

CompanyName: Adobe Systems, Inc.
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
FileVersion: 10,1,53,64
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
LegalTrademarks: Adobe? Flash? Player
OriginalFilename: FlashUtil.exe
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
Translation: 0x0409 0x04b0

Troj/DwnLdr-MDK also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Razy.448218
FireEyeGeneric.mg.a920f5d60e37cfd0
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeDownloader-BIJ.a
MalwarebytesGeneric.Trojan.Injector.DDS
VIPREGen:Variant.Razy.448218
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.448218
K7GWTrojan ( 0053a0a21 )
K7AntiVirusTrojan-Downloader ( 0040f54b1 )
ArcabitTrojan.Razy.D6D6DA
BitDefenderThetaGen:NN.ZexaF.36196.cq0@a0LUH!ci
CyrenW32/Rubin.A.gen!Eldorado
SymantecTrojan.Cryect
Elasticmalicious (high confidence)
ESET-NOD32Win32/Injector.BFSU
APEXMalicious
ClamAVWin.Trojan.Ulise-6838227-0
KasperskyHEUR:Trojan.Win32.Miancha.gen
NANO-AntivirusTrojan.Win32.Small.cpbmb
ViRobotTrojan.Win32.Downloader.36864.PZ
RisingTrojan.Injector!1.A7C6 (CLASSIC)
SophosTroj/DwnLdr-MDK
BaiduWin32.Trojan.Inject.bm
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad2.15318
ZillyaTrojan.MianchaGen.Win32.2
TrendMicroBKDR_SIMBOT.SMJB
McAfee-GW-EditionBehavesLike.Win32.Downloader.nm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.448218 (B)
IkarusTrojan-Downloader.Win32.Small
JiangminTrojanDownloader.Small.ajux
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Inject.aaceh
XcitiumBackdoor.Win32.Simbot.FTSP@5j7zlt
MicrosoftTrojan:Win32/Injector.ARA!MTB
SUPERAntiSpywareBackdoor.Bot/Variant
ZoneAlarmHEUR:Trojan.Win32.Miancha.gen
GDataWin32.Trojan.PSE1.13MYFBD
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.CSon.R885
Acronissuspicious
VBA32BScope.Trojan.Miancha
ALYacGen:Variant.Razy.448218
TACHYONTrojan/W32.Agent.36864.BSC
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_SIMBOT.SMJB
TencentTrojan.Win32.Miancha.za
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Inject.AACEH
FortinetMalwThreat!d8f5IV
AVGWin32:KeyIso-A [Trj]
AvastWin32:KeyIso-A [Trj]

How to remove Troj/DwnLdr-MDK?

Troj/DwnLdr-MDK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment