Trojan

Trojan:MSIL/Mardom.BNAA!MTB information

Malware Removal

The Trojan:MSIL/Mardom.BNAA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Mardom.BNAA!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:MSIL/Mardom.BNAA!MTB?


File Info:

name: 2E08B07F377DAAA90CD4.mlw
path: /opt/CAPEv2/storage/binaries/016d6820a72c6809167a333e549b916ac9c7d79a1d2645384786f14b5ec8b2b5
crc32: 0CFF52E2
md5: 2e08b07f377daaa90cd4e255927b4156
sha1: 2c322ecf8d2ab4e0b049bd413238dbec1d9663f6
sha256: 016d6820a72c6809167a333e549b916ac9c7d79a1d2645384786f14b5ec8b2b5
sha512: d11da5438f46024370a82d7d5ffa630e4d31fa00fe25983bcca3fea034d4d9c992b76b5c4cab661d76d8ee24684323a17f8e029728a450a747259c8d0acf15f1
ssdeep: 1536:9BdsPGI/VimqV4o2DKOnZjuWrQEIPX4ZZaWYgg:9oRgfSbcX4Zkngg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E83C617BA5A88F1C2855B7AC98F500C0364DE83F6E3D74E798E139615C37EA8D01E4B
sha3_384: df4c521eb5d11bb3a6a21c1a04a3ca022478982732a668a546d1035f1fcfd356ba87bcf9b0f77af43d223f63d73aaf93
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-01-19 19:37:22

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: builder.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: builder.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/Mardom.BNAA!MTB also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.141316
FireEyeGeneric.mg.2e08b07f377daaa9
SkyhighBehavesLike.Win32.Generic.mm
McAfeeArtemis!2E08B07F377D
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.MSILHeracles.D22804
VirITTrojan.Win32.MSIL_Heur.A
SymantecMSIL.Downloader!gen7
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.QET
APEXMalicious
BitDefenderGen:Variant.MSILHeracles.141316
AvastWin32:DropperX-gen [Drp]
F-SecureHeuristic.HEUR/AGEN.1323343
DrWebTrojan.DownLoaderNET.922
VIPREGen:Variant.MSILHeracles.141316
EmsisoftGen:Variant.MSILHeracles.141316 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
GoogleDetected
AviraHEUR/AGEN.1323343
VaristW32/MSIL_Agent.HIY.gen!Eldorado
Antiy-AVLTrojan[Downloader]/MSIL.Agent
Kingsoftmalware.kb.c.981
MicrosoftTrojan:MSIL/Mardom.BNAA!MTB
GDataGen:Variant.MSILHeracles.141316
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZemsilF.36680.fm0@aSce2Eh
ALYacGen:Variant.MSILHeracles.141316
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Agent.QES!tr.dldr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Mardom.BNAA!MTB?

Trojan:MSIL/Mardom.BNAA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment