Trojan

Trojan:Win32/BazarLoader.B!MTB (file analysis)

Malware Removal

The Trojan:Win32/BazarLoader.B!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BazarLoader.B!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/BazarLoader.B!MTB?


File Info:

name: 084164CB7C70DDB22F9E.mlw
path: /opt/CAPEv2/storage/binaries/c91d6f1f6df6e5e7d140ca07c2b8053b68f029bdceafaa9df0c5ff29a755d13b
crc32: 8FFECE58
md5: 084164cb7c70ddb22f9ec3372dd83794
sha1: a3a9d26876c8870b89f7a7e4bb6d7b881722f08f
sha256: c91d6f1f6df6e5e7d140ca07c2b8053b68f029bdceafaa9df0c5ff29a755d13b
sha512: f2b12f4ca535b89893f76e85eb98686c681258caec9d084222633286a388d60259bfb75633cfdb5c891027ef2050674dedaf19f8baa7fc9fb672e2ad260ce120
ssdeep: 6144:wBlL/9az6S76/CVhj2pfOBZQXQLCE/PiNPL2o8l3AsLuWQbu8fF1VJTOX:C/amIj21gQKCEHYCou+dJSX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B584235A67E1CDFFD1FA00301972C35EC3B66B085A27A1832FA54F7EA8712D7B845642
sha3_384: 2cc28102069c27d56dfdce10594338454dc7efbf5644a423c31f4537544cb3ce33e0f548c63fb7e2c09634359588a88a
ep_bytes: 81ec840100005355565733db68018000
timestamp: 2016-04-02 03:20:05

Version Info:

CompanyName: magazine
FileDescription: magazine
FileVersion: 1.0.1.120
ProductName: Mmagazine
ProductVersion: 1.0.1.120
Translation: 0x0409 0x04e4

Trojan:Win32/BazarLoader.B!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Strab.4!c
DrWebTrojan.Inject4.64405
MicroWorld-eScanTrojan.GenericKD.70405661
FireEyeGeneric.mg.084164cb7c70ddb2
SkyhighBehavesLike.Win32.Dropper.fc
ALYacTrojan.GenericKD.70405661
Cylanceunsafe
SangforTrojan.Win32.Bazarloader.Vi8r
K7AntiVirusTrojan ( 005adf8f1 )
AlibabaTrojan:Win32/Strab.a84853e9
K7GWTrojan ( 005adf8f1 )
ArcabitTrojan.Generic.D4324E1D
VirITTrojan.Win32.Agent.DVA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ETLW
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.Strab.dlu
BitDefenderTrojan.GenericKD.70405661
NANO-AntivirusTrojan.Win32.Strab.kdsddt
AvastWin32:DropperX-gen [Drp]
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.dspbz
VIPRETrojan.GenericKD.70405661
TrendMicroBackdoor.Win32.REMCOS.YXDKPZ
EmsisoftTrojan.GenericKD.70405661 (B)
SentinelOneStatic AI – Suspicious PE
VaristW32/Trojan.SUZJ-8932
AviraTR/Redcap.dspbz
Antiy-AVLTrojan/Win32.Injector
Kingsoftmalware.kb.a.757
MicrosoftTrojan:Win32/BazarLoader.B!MTB
ZoneAlarmTrojan.Win32.Strab.dlu
GDataWin32.Trojan.Agent.BAPXFE
GoogleDetected
AhnLab-V3Trojan/Win.InjectorX-gen.R622016
McAfeeArtemis!084164CB7C70
MAXmalware (ai score=82)
MalwarebytesTrojan.Injector.NSIS
PandaTrj/Chgt.AD
TrendMicro-HouseCallBackdoor.Win32.REMCOS.YXDKPZ
RisingTrojan.BazarLoader!8.121BC (TFE:5:bBuYwgsGkHK)
YandexTrojan.Igent.b1dlFi.13
IkarusTrojan.Win32.Injector
FortinetNSIS/Agent.DCAC!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/BazarLoader.B!MTB?

Trojan:Win32/BazarLoader.B!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment