Trojan

Trojan:Win32/Trickster.DHA!MTB removal instruction

Malware Removal

The Trojan:Win32/Trickster.DHA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Trickster.DHA!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Trickster.DHA!MTB?


File Info:

name: 0D8427B7AD10F95539C2.mlw
path: /opt/CAPEv2/storage/binaries/2610797b258f6fbc974c389f2c76ae291197753f8f67ad74eccbfcc064760279
crc32: 03BD26DF
md5: 0d8427b7ad10f95539c259eb1e00c414
sha1: ab3920838f6c617fb64e1cdbc6a9085e1fac32b6
sha256: 2610797b258f6fbc974c389f2c76ae291197753f8f67ad74eccbfcc064760279
sha512: 3a95a35306f260b7e1e3b9c1cad8f99e88b017b8916d91219206e93c9227555740d0411b08038959b254e8f2816ce7b0a56ff6beffe5a338f9690425845fb828
ssdeep: 12288:W2j4y1eRkNnrHu8wDT2zV9o8I+VPSgCnE:W2HJn+T0Xo8I+V6gCnE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187B428C73A63D43AE806077DC60AC9BDC93E7E0DBA329087A7D707CF66352D58121969
sha3_384: f6a0f0f968d20c9db9f3601f0207702a599fd49999ed9b763a9c75c321cc69f4c0d1208358aeb423a7e455fec1078661
ep_bytes: e8d9880000e917feffff8b44240433c9
timestamp: 2006-11-08 12:02:23

Version Info:

FileVersion: 3.8.75.97
CompanyName: IderaStory
FileDescription: BreadBottom sol
OriginalFilename: Nightproduce.exe
LegalCopyright: Copyright (c) 2006-2014, himnoisenor IderaStory
ProductName: BreadBottom sol
ProductVersion: 3.8.75.97
LegalTrademarks: BreadBottom sol
InternalName: BreadBottom sol
Translation: 0x0409 0x04b0

Trojan:Win32/Trickster.DHA!MTB also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.200489
FireEyeGeneric.mg.0d8427b7ad10f955
McAfeeArtemis!0D8427B7AD10
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Generik.EFFSYRI
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Johnnie.200489
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34232.Eq0@aK8@fuki
VirITTrojan.Win32.Injector.CTOO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.EFFSYRI
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.ammbd
AlibabaTrojan:Win32/Trickster.4dc2e880
NANO-AntivirusTrojan.Win32.Inject.ghkwzu
RisingTrojan.Trickbot!8.E313 (CLOUD)
Ad-AwareGen:Variant.Johnnie.200489
ZillyaTrojan.Inject.Win32.299898
TrendMicroTROJ_GEN.R002C0DL121
EmsisoftGen:Variant.Johnnie.200489 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.bduc
WebrootW32.Trojan.Gen
AviraTR/Injector.wzikx
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.2CF27CE
MicrosoftTrojan:Win32/Trickster.DHA!MTB
ZoneAlarmTrojan.Win32.Inject.ammbd
GDataGen:Variant.Johnnie.200489
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C3555953
VBA32Trojan.Inject
ALYacTrojan.Trickster.Gen
MalwarebytesMalware.AI.3759631551
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DL121
TencentWin32.Trojan.Inject.Hyy
YandexTrojan.Inject!I7G7pMLaqPI
IkarusTrojan.SuspectCRC
FortinetW32/GenKryptik.ENJS!tr
AVGFileRepMalware
Cybereasonmalicious.7ad10f
AvastFileRepMalware
MaxSecureTrojan.Malware.74686726.susgen

How to remove Trojan:Win32/Trickster.DHA!MTB?

Trojan:Win32/Trickster.DHA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment