Trojan

Trojan:Win32/BadJoke.PA!MTB (file analysis)

Malware Removal

The Trojan:Win32/BadJoke.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BadJoke.PA!MTB virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

pesda.tk

How to determine Trojan:Win32/BadJoke.PA!MTB?


File Info:

crc32: B4E7869C
md5: 896db1eecce8a07f4693cc24c5ce2742
name: uber.exe
sha1: cd1bd6ad293f9a6b1c07724bd57099e0475f5794
sha256: 2b54e101517d206835ba02b121d824e0d11e6ad0f833aad15c01bd3b9434b04a
sha512: 2940dbf42369046bd6056f38b7301eefe42ca7d336d00c15327af8afe2bad8d015ffb8cfc6f1a84b78b5b31d41955ceaa9f6432bc6e9b2db4cb5bb0b2eaa323c
ssdeep: 96:7GxFl2F2kJ1pSVGu1W5xnAisSCrei/E2PqsmA3Nf/F09/HDjOEB:0wyVG6axnAi1C/E2is33Nfq9/DjO
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/BadJoke.PA!MTB also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGeneric.Malware.dld!!.C08A552F
FireEyeGeneric.mg.896db1eecce8a07f
McAfeeArtemis!896DB1EECCE8
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Small!cobra (v)
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGeneric.Malware.dld!!.C08A552F
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ecce8a
TrendMicroTROJ_GEN.R002C0DCB20
BitDefenderThetaGen:NN.ZexaF.34104.amW@aatNRop
F-ProtW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/BadJoke.HC
TrendMicro-HouseCallTROJ_GEN.R002C0DCB20
AvastWin32:Malware-gen
GDataGeneric.Malware.dld!!.C08A552F
KasperskyTrojan.Win32.SchoolGirl.eko
AlibabaTrojan:Win32/SchoolGirl.8e06f85b
NANO-AntivirusTrojan.Win32.SchoolGirl.getfws
AegisLabTrojan.Win32.Malicious.4!c
TencentWin32.Trojan.Schoolgirl.Ebhd
Ad-AwareGeneric.Malware.dld!!.C08A552F
SophosMal/Generic-S
F-SecureTrojan.TR/SchoolGirl.vauvq
DrWebTrojan.KillFiles.64654
ZillyaTool.HC.Win32.20
McAfee-GW-EditionBehavesLike.Win32.Dropper.xm
SentinelOneDFI – Suspicious PE
EmsisoftGeneric.Malware.dld!!.C08A552F (B)
APEXMalicious
CyrenW32/Downloader-Sml!Eldorado
MaxSecureTrojan.Malware.1728101.susgen
AviraTR/SchoolGirl.vauvq
Antiy-AVLTrojan/Win32.SchoolGirl
Endgamemalicious (high confidence)
ArcabitGeneric.Malware.dld!!.C08A552F
AhnLab-V3Malware/Win32.Generic.C3496343
ZoneAlarmTrojan.Win32.SchoolGirl.eko
MicrosoftTrojan:Win32/BadJoke.PA!MTB
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGeneric.Malware.dld!!.C08A552F
MAXmalware (ai score=85)
PandaTrj/GdSda.A
RisingTrojan.Wacatac!8.10C01 (CLOUD)
YandexTrojan.SchoolGirl!
IkarusTrojan-Downloader.Win32.Small
FortinetW32/SchoolGirl.EKO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM20.1.3CCF.Malware.Gen

How to remove Trojan:Win32/BadJoke.PA!MTB?

Trojan:Win32/BadJoke.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment