Trojan

About “Trojan:Win32/BazarLoader.B!MTB” infection

Malware Removal

The Trojan:Win32/BazarLoader.B!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BazarLoader.B!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Formbook malware family
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/BazarLoader.B!MTB?


File Info:

name: 98F94D511B749D11B6C1.mlw
path: /opt/CAPEv2/storage/binaries/cb5f546b3b10a5b17ad291d0cc3d39293a0bf874ced046e5390f85110d518e02
crc32: 15706C9B
md5: 98f94d511b749d11b6c1732ed4a06501
sha1: 529ea9cb5d0945646395ffa7c8250e1b0b915f51
sha256: cb5f546b3b10a5b17ad291d0cc3d39293a0bf874ced046e5390f85110d518e02
sha512: 249ea90f4df59cc7228b7ce6e3d908372cee98a3369dba3ec874b9a04f724aa839202d05b9eaf3ee6c946a414f9a75f7def9cd42324ab6d9b0856b9871bc2d89
ssdeep: 12288:HfrKYLQE7FlilNqvSlNErhfep0tLt+ir3qt7:DKZUmNERoULt/3g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F084235206C3E927C1EA27315DAF976AE3744C04015137C763A46FAB3E726D78C2EA9C
sha3_384: 64cb1246840ee265b51a916cf277830a45b81641618720e225327bdc107be4b9916c3d6c076764e63d0b3feea7184090
ep_bytes: 81ec840100005355565733db68018000
timestamp: 2016-04-02 03:20:05

Version Info:

CompanyName: magazine
FileDescription: magazine
FileVersion: 1.0.1.120
ProductName: Mmagazine
ProductVersion: 1.0.1.120
Translation: 0x0409 0x04e4

Trojan:Win32/BazarLoader.B!MTB also known as:

BkavW32.Common.08FDDFEE
LionicTrojan.Win32.Strab.4!c
DrWebTrojan.Siggen22.6400
MicroWorld-eScanMemScan:Trojan.GenericKDZ.104178
FireEyeGeneric.mg.98f94d511b749d11
CAT-QuickHealTrojan.Strab
SkyhighBehavesLike.Win32.Generic.fc
ALYacMemScan:Trojan.GenericKDZ.104178
MalwarebytesTrojan.Injector.NSIS
K7AntiVirusTrojan ( 005ade741 )
AlibabaTrojan:Win32/BazarLoader.8c690a4d
K7GWTrojan ( 005ade741 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D196F2
BitDefenderThetaGen:NN.ZexaF.36792.quW@aKh!Yrf
VirITTrojan.Win32.GenusT.DTQY
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ETLV
CynetMalicious (score: 99)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Strab.gen
BitDefenderMemScan:Trojan.GenericKDZ.104178
NANO-AntivirusTrojan.Win32.Strab.kdqahw
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan.Strab.Kcnw
SophosMal/Generic-S
F-SecureTrojan.TR/Injector.tksob
VIPREMemScan:Trojan.GenericKDZ.104178
EmsisoftMemScan:Trojan.GenericKDZ.104178 (B)
IkarusTrojan-Spy.FormBook
JiangminTrojan.Strab.chl
WebrootW32.Trojan.Gen
VaristW32/Strab.L.gen!Eldorado
AviraTR/Redcap.ogdwj
Antiy-AVLGrayWare/Win32.Wacapew
KingsoftWin32.Trojan.Strab.gen
XcitiumMalware@#1cwt2ve10afwg
MicrosoftTrojan:Win32/BazarLoader.B!MTB
ZoneAlarmHEUR:Trojan.Win32.Strab.gen
GDataWin32.Trojan.Agent.YDS5RA
GoogleDetected
AhnLab-V3Trojan/Win.InjectorX-gen.R621879
McAfeeArtemis!98F94D511B74
MAXmalware (ai score=88)
VBA32BScope.Trojan.Idunn
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CKE23
RisingTrojan.Strab!8.12D03 (TFE:5:sjSCW5ImPdU)
YandexTrojan.Strab!R6YacoIz9eo
SentinelOneStatic AI – Suspicious PE
FortinetNSIS/Agent.DCAC!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/BazarLoader.B!MTB?

Trojan:Win32/BazarLoader.B!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment