Trojan

How to remove “Trojan:Win32/Blihan.MA!MTB”?

Malware Removal

The Trojan:Win32/Blihan.MA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Blihan.MA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Blihan.MA!MTB?


File Info:

name: 4F081AE9248206AAFB74.mlw
path: /opt/CAPEv2/storage/binaries/5dc569610db382bb9c9b61c60337783ef3f894c8f2bc37ee4a31c2be80255ca6
crc32: F0A338DA
md5: 4f081ae9248206aafb74ea144927957a
sha1: 37f6a32a6603706606d50f8ecfb3283e5b379ae2
sha256: 5dc569610db382bb9c9b61c60337783ef3f894c8f2bc37ee4a31c2be80255ca6
sha512: ad0603648a15971cb794cd43f17eb099f9b2b0649ea358273eb14710bf510740763bc5d989f48e667a14f5cf13dfdc369f6198329ce393f02a800600304f3294
ssdeep: 384:Px2KzC6+1ihcz/A78FBPgy7pYQ67HZp9zO0gWRqpd+/rhBbx0A0kH:S6wTz/A780qpoHZplRRqpd6rnxn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2239F1379D28473E1D1117204AA5F7A9B3F3D121FF05987CB9CEE292A726909D3628B
sha3_384: 3a0a49298d4406d12d72fa1e773cf1171265d1bae4f045140b8206628bec9c2c9f783e5b712c51a001f09a916a6cdf91
ep_bytes: 00000000000000000000000000000000
timestamp: 2012-01-19 04:28:47

Version Info:

0: [No Data]

Trojan:Win32/Blihan.MA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.778630
FireEyeGeneric.mg.4f081ae9248206aa
ALYacGen:Variant.Graftor.778630
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPREGen:Variant.Graftor.778630
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Agent.BRN.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Graftor.778630
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastFileRepMalware [Misc]
EmsisoftGen:Variant.Graftor.778630 (B)
BaiduWin32.Trojan.Agent.el
TrendMicroTROJ_GEN.R03BC0DEK23
McAfee-GW-EditionBehavesLike.Win32.Generic.pt
Trapminemalicious.high.ml.score
SophosTroj/Domkop-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.778630
MAXmalware (ai score=85)
XcitiumPacked.Win32.Klone.~KH@1kg7s2
ArcabitTrojan.Graftor.DBE186
MicrosoftTrojan:Win32/Blihan.MA!MTB
GoogleDetected
Acronissuspicious
McAfeeGenericRXAA-FA!4F081AE92482
TACHYONTrojan/W32.Agent.49152.DAY
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DEK23
RisingTrojan.Agent!1.DC48 (CLASSIC)
IkarusTrojan.Win32.Blihan
MaxSecureTrojan.Malware.185915194.susgen
FortinetW32/Graftor.778630!tr
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Blihan.MA!MTB?

Trojan:Win32/Blihan.MA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment