Trojan

Trojan:Win32/DanaBot.AT!MTB removal tips

Malware Removal

The Trojan:Win32/DanaBot.AT!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/DanaBot.AT!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua
cjto.top

How to determine Trojan:Win32/DanaBot.AT!MTB?


File Info:

crc32: BF387663
md5: ac8f8be2d94d5583c7d43a1e9f2e7896
name: tmpm0lfwmp7
sha1: fcd45014b3df0f941282fabc9cb848971791f82e
sha256: 20ebe8ff1da6f2023a43b3e3cbe14479961699f9dec0324f72070fa2b275eaae
sha512: 8eb20c02b6dc980e128d95dfe0d7b11ecd3ad46cbd4ed274632f80bd0aab8390a042e61880b40569cb3da60b22e4ec5da258e5250de825555962943f7fc9e1ed
ssdeep: 12288:njljnPk+5OPGaJ31Sp7GZZlW+vDwCfFkij5tehXA7msV5I3AIR07CP:jlt5OPGs09mZ3vDd1ltNCZ0e
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: asf3vswgakv.ixe
FileVersionOld: 1.2.0.1
ProductVersion: 1.0.4.1
Copyrighd: Copyrighd (C) 2020, odfgbiv
Translation: 0x0842 0x04c4

Trojan:Win32/DanaBot.AT!MTB also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.43354517
McAfeePacked-GBO!AC8F8BE2D94D
CylanceUnsafe
AegisLabAdware.Win32.Generic.mCzN
SangforMalware
K7AntiVirusTrojan ( 005690f31 )
BitDefenderTrojan.GenericKD.43354517
K7GWTrojan ( 005690f31 )
Cybereasonmalicious.4b3df0
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34128.Xq0@aeeyhgec
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HEDI
TrendMicro-HouseCallRansom_Stop.R02DC0DFJ20
Paloaltogeneric.ml
GDataTrojan.GenericKD.43354517
KasperskyTrojan-Ransom.Win32.Stop.nu
AlibabaTrojan:Win32/DanaBot.e093a425
NANO-AntivirusTrojan.Win32.Kryptik.hlgkim
APEXMalicious
RisingRansom.Stop!8.10810 (CLOUD)
Ad-AwareTrojan.GenericKD.43354517
EmsisoftTrojan.GenericKD.43354517 (B)
ComodoMalware@#2wx3bzydo20ld
DrWebTrojan.Siggen9.48175
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Stop.R02DC0DFJ20
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.ac8f8be2d94d5583
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
MAXmalware (ai score=89)
Antiy-AVLTrojan[Ransom]/Win32.Stop
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2958995
AhnLab-V3Trojan/Win32.MalPe.R340656
ZoneAlarmTrojan-Ransom.Win32.Stop.nu
MicrosoftTrojan:Win32/DanaBot.AT!MTB
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Wacatac
ALYacTrojan.Ransom.Stop
MalwarebytesTrojan.MalPack
AvastWin32:DropperX-gen [Drp]
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HEDU!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Ransom.96a

How to remove Trojan:Win32/DanaBot.AT!MTB?

Trojan:Win32/DanaBot.AT!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment