Trojan

What is “Trojan:Win32/Neoreklami.AD!MTB”?

Malware Removal

The Trojan:Win32/Neoreklami.AD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Neoreklami.AD!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Neoreklami.AD!MTB?


File Info:

name: 956347200AAD298F125D.mlw
path: /opt/CAPEv2/storage/binaries/3a29a85978846928c2189de45362c5d188fbedaea700cb83e1ed11e4f10a2f0c
crc32: C65A022A
md5: 956347200aad298f125d7f1d05959c45
sha1: a66fc1451cbadce144d6662de5680448b0e8b8b9
sha256: 3a29a85978846928c2189de45362c5d188fbedaea700cb83e1ed11e4f10a2f0c
sha512: 05bc3126a98a5f70483da3f3a4fc7cc2eb619704414edaa2b4481ba7a3fcb7c413b41a2a3d371e8e113f90fe76ad95990595dd1811b379055b6455142bd61be9
ssdeep: 196608:O7qZU2yrGYxyyzc0GMee0ZgfR70San0U/GiHCuhgz58AVKzC:8f6oyGrGte8g5ASHU/Xly1VK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127661229B341E12AD49110F733ADAAAD41E47B30153944ABFFC0AB0D7DF4AD6D922763
sha3_384: 19e1062f5b32e48495e44dd6f4296693149cf3776e473cb683f24019b92e3f89688afb2c36b9bcc6e6ee42a2d7571882
ep_bytes: e8f2ca0000e97ffeffffe8cf9d00008b
timestamp: 2021-03-12 10:17:41

Version Info:

0: [No Data]

Trojan:Win32/Neoreklami.AD!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Sdum.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.396076
FireEyeGeneric.mg.956347200aad298f
CAT-QuickHealPUA.NeoreklamiRI.S20793814
McAfeeGenericRXOP-HH!956347200AAD
CylanceUnsafe
ZillyaAdware.Neoreklami.Win32.24889
SangforTrojan.Win32.GenericML.xnet
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CyrenW32/Neoreklami.H.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.KY
APEXMalicious
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderGen:Variant.Zusy.396076
NANO-AntivirusRiskware.Win32.Neoreklami.ivobyo
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Zusy.396076
SophosGeneric PUA KG (PUA)
DrWebTrojan.BPlug.3929
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Variant.Zusy.396076 (B)
IkarusPUA.Neoreklami
GDataGen:Variant.Zusy.396076
JiangminTrojan.Multi.anu
AviraHEUR/AGEN.1140029
MAXmalware (ai score=83)
Antiy-AVLGrayWare[AdWare]/Win32.Neoreklami
ArcabitTrojan.Zusy.D60B2C
MicrosoftTrojan:Win32/Neoreklami.AD!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CryptInject.R370614
ALYacGen:Variant.Zusy.396076
VBA32Trojan.Sabsik.FT
MalwarebytesAdware.Neoreklami
RisingTrojan.Generic@ML.89 (RDML:6joilQmBQduNB3wBqqSAdg)
YandexPUA.Neoreklami!RwEBzTCttcg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/Neoreklami.KR
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.82199810.susgen

How to remove Trojan:Win32/Neoreklami.AD!MTB?

Trojan:Win32/Neoreklami.AD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment