Trojan

Trojan:Win32/DanaBot.AV!MTB removal

Malware Removal

The Trojan:Win32/DanaBot.AV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/DanaBot.AV!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Trojan:Win32/DanaBot.AV!MTB?


File Info:

crc32: 656118D8
md5: 6a7a1fc3678fa67442d0c4560a2f708b
name: love.exe
sha1: 37964bf370fe9032ede8ea266b10fea5c47e8f57
sha256: cb74b5b6103dc8b1916b9058ee7ad85048f84b948f518fbf270c8881a4227f3c
sha512: f73700ae44744e272176780cb7f37847c77d68fc8d073e3c2afe60ee93a3a6b18c6b81377d6f6c31044ceefd42c1e02035fd4c59251417145ae84a93934fe2bd
ssdeep: 12288:EOoSGQk7sQ6PP3jAw//qCYH1xmLyg+UmHRJJ:zinsHPPTnnczg+HRz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: oczmxpwvesv.ixe
FileVersionOld: 1.2.0.1
ProductVersion: 1.0.4.1
Copyrighd: Copyrighd (C) 2020, odfgbiv
Translation: 0x0842 0x04c4

Trojan:Win32/DanaBot.AV!MTB also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.43360700
FireEyeGeneric.mg.6a7a1fc3678fa674
McAfeeRDN/Generic.grp
MalwarebytesTrojan.MalPack.GS
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0056919a1 )
BitDefenderTrojan.GenericKD.43360700
K7GWTrojan ( 0056919a1 )
Cybereasonmalicious.370fe9
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34128.HC0@a0Jyv!lc
CyrenW32/Wacatac.BV.gen!Eldorado
SymantecML.Attribute.HighConfidence
AvastWin32:CoinminerX-gen [Trj]
GDataTrojan.GenericKD.43360700
KasperskyTrojan-PSW.Win32.Racealer.gle
AlibabaTrojanPSW:Win32/Racealer.7024eafb
APEXMalicious
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgXIsH/Y06Iqaw)
Ad-AwareTrojan.GenericKD.43360700
SophosMal/GandCrab-G
DrWebTrojan.PWS.Stealer.28520
TrendMicroTROJ_GEN.R014C0DFK20
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.hc
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.43360700 (B)
IkarusTrojan.Win32.Crypt
F-ProtW32/Wacatac.BV.gen!Eldorado
MAXmalware (ai score=86)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D295A1BC
ZoneAlarmTrojan-PSW.Win32.Racealer.gle
MicrosoftTrojan:Win32/DanaBot.AV!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R340930
Acronissuspicious
ALYacTrojan.GenericKD.43360700
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HEEN
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.HEDU!tr
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.PSW.b4a

How to remove Trojan:Win32/DanaBot.AV!MTB?

Trojan:Win32/DanaBot.AV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment