Trojan

Trojan.Mardom.PN.24 information

Malware Removal

The Trojan.Mardom.PN.24 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Mardom.PN.24 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

karuga.no-ip.org

How to determine Trojan.Mardom.PN.24?


File Info:

crc32: 124FC17D
md5: 71378c3ed390b641f4866a821054db30
name: 71378C3ED390B641F4866A821054DB30.mlw
sha1: 10f2f4f04583006e7314b226e39dfa34315e3228
sha256: 097add5a10ea8b9cd76f773d3b3051aab9987f83844d6725065c573a80859d78
sha512: ebf9fb024d43613bcd10c746975e9387575c8c710d7fd76c1b200d0a3132e91eb2ac8cc7f077abca22b05b8f26990936d4a3b91a3e8434808128f7f7658ca2ac
ssdeep: 1536:6G50RJAsjHJxEphcx2yWQzGHxoA7oeP0apCsCV46vNz5FQ:6jJzjpxEpOcN3HxoAMDaizM
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Z686gqL2BmxT0J11WMbuF6587an0y832
Assembly Version: 2.4.7.9
InternalName: C:UsersPowerStationDesktopstub.exe
FileVersion: 0.8.2.5
CompanyName: Bl1UOiwnUiA47N1aN645H6qK6Nd09c7DIBSrXYF39c0
LegalTrademarks: microsoft
Comments: Windows disktop Manager
ProductName: LFsL1bAJQQ6bXd04lZrAp3aX5rqUHQAp
ProductVersion: 2.4.7.9
FileDescription: nn8qVWzAm620011NZjtRkyQ84TaG4t30s4W6cG92EIM
OriginalFilename: C:UsersPowerStationDesktopstub.exe

Trojan.Mardom.PN.24 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.25074
CynetMalicious (score: 100)
ALYacGen:Trojan.Mardom.PN.24
CylanceUnsafe
ZillyaTrojan.Injector.Win32.398500
SangforBackdoor.MSIL.Generic.ky
AlibabaBackdoor:MSIL/Injector.740fb221
Cybereasonmalicious.045830
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.BGO
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.MSIL.Generic
BitDefenderGen:Trojan.Mardom.PN.24
NANO-AntivirusTrojan.Win32.Autoruner.cujbcm
MicroWorld-eScanGen:Trojan.Mardom.PN.24
TencentWin32.Trojan.Generic.Aedz
Ad-AwareGen:Trojan.Mardom.PN.24
SophosMal/Generic-S
ComodoMalware@#2hnrn1cm2ovpt
BitDefenderThetaGen:NN.ZemsilF.34236.hq0@aye@dam
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-FAYU!71378C3ED390
FireEyeGeneric.mg.71378c3ed390b641
EmsisoftGen:Trojan.Mardom.PN.24 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cboaq
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1128487
eGambitGeneric.Malware
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Trojan.Mardom.PN.24
Acronissuspicious
McAfeePWS-FAYU!71378C3ED390
MAXmalware (ai score=100)
VBA32Hoax.Blocker
PandaTrj/CI.A
RisingTrojan.Generic@ML.100 (RDML:ZwO4WYns0H2AffsI574J+A)
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.BQZ!tr
AVGWin32:Malware-gen

How to remove Trojan.Mardom.PN.24?

Trojan.Mardom.PN.24 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment