Trojan

Trojan:MSIL/Androm.D!MTB removal tips

Malware Removal

The Trojan:MSIL/Androm.D!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Androm.D!MTB virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking

How to determine Trojan:MSIL/Androm.D!MTB?


File Info:

crc32: 40DB7944
md5: 70922f8845c1158f5836bb4823e38741
name: 70922F8845C1158F5836BB4823E38741.mlw
sha1: fd11f731e7e8c888a996a7170fec20a7af002c35
sha256: 9150f2e06808a7295367f76db4f4e2e378b074db1f972d76d8c8097db57ed17c
sha512: 09b4d546be6b30d5d0f808b49097cc68c5697454cf2b17016748bb4d2d8f8702e20e9100529d311883c7f52a0593501ec75616220a91eb522cd559776f47212b
ssdeep: 3072:2QB1jZi2hz2QfIRi2qL4ROUpOvaZECBxB2FkZllwQ0C7TOacVxNqnDon4:2QPZ1V2Qt7wprERkreQ0UWqnDon
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: hoi
Assembly Version: 12.3.34.4
InternalName: jk.exe
FileVersion: 34.3.9.0
CompanyName: h
LegalTrademarks: h
Comments: uhh
ProductName: io
ProductVersion: 34.3.9.0
FileDescription: ir
OriginalFilename: jk.exe

Trojan:MSIL/Androm.D!MTB also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.3459
CynetMalicious (score: 85)
ALYacGen:Variant.Ransom.Samas.9
MalwarebytesMalware.AI.4091201883
ZillyaTrojan.Injector.Win32.783248
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Androm.5cfbc1df
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.845c11
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.ERL
APEXMalicious
AvastMSIL:GenMalicious-ARE [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Samas.9
NANO-AntivirusTrojan.Win32.Drop.dzsyxq
MicroWorld-eScanGen:Variant.Ransom.Samas.9
TencentWin32.Trojan.Generic.Agba
Ad-AwareGen:Variant.Ransom.Samas.9
SophosMal/Generic-S + Troj/MSIL-EGP
ComodoMalware@#1pi06zvkpfq35
BitDefenderThetaGen:NN.ZemsilF.34628.lm0@a8L!gSl
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXLF-FM!70922F8845C1
FireEyeGeneric.mg.70922f8845c1158f
EmsisoftGen:Variant.Ransom.Samas.9 (B)
JiangminTrojan.Generic.gkkoh
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:MSIL/Androm.D!MTB
ArcabitTrojan.Ransom.Samas.9
AegisLabTrojan.Win32.FrauDrop.b!c
GDataGen:Variant.Ransom.Samas.9
McAfeeGenericRXLF-FM!70922F8845C1
MAXmalware (ai score=81)
VBA32TrojanDropper.FrauDrop
PandaTrj/CI.A
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.DR.FrauDrop!6SI0hlj9PzA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Kryptik.TR!tr
AVGMSIL:GenMalicious-ARE [Trj]
Qihoo-360Win32/TrojanDropper.Generic.HgIASOcA

How to remove Trojan:MSIL/Androm.D!MTB?

Trojan:MSIL/Androm.D!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment