Threat Database Trojans Trojan.MSIL.Mardom.BG

Trojan.MSIL.Mardom.BG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,550
Threat Level: 80 % (High)
Infected Computers: 15
First Seen: August 14, 2025
Last Seen: April 25, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Mardom.BG on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.MSIL.Mardom.BG?

Trojan.MSIL.Mardom.BG is a type of Trojan horse malware that can infect your computer without your knowledge or consent. The name "Trojan" refers to the fact that this malware disguises itself as a legitimate program or file, allowing it to bypass security measures and gain access to your system. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic language used by the .NET Framework.

How Trojan.MSIL.Mardom.BG Operates

Once installed, Trojan.MSIL.Mardom.BG can operate in various ways, depending on its intended purpose. It may attempt to steal sensitive information, such as login credentials, credit card numbers, or personal data. It can also install additional malware, create backdoors for remote access, or disrupt system performance. In some cases, it may even recruit your computer into a botnet, allowing it to participate in distributed denial-of-service (DDoS) attacks or other malicious activities.

Symptoms of Infection

Identifying a Trojan.MSIL.Mardom.BG infection can be challenging, as it often disguises itself as a legitimate program. However, some common symptoms may include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups. You may also notice unfamiliar programs or icons on your desktop, or receive alerts from your security software indicating suspicious activity.

  • Unexplained changes to your system settings or configuration
  • Increased network activity or unusual traffic patterns
  • Appearance of unfamiliar files or folders on your computer
  • Difficulty accessing certain websites or online services

How to Remove Trojan.MSIL.Mardom.BG

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Mardom.BG from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and maintain the security and integrity of your computer. Remember to always be cautious when downloading software or files from the internet, and to keep your operating system and security software up to date to ensure the best possible protection against malware threats.

Analysis Report

General information

Family Name: Trojan.MSIL.Mardom.BG
Signature status: Hash Mismatch

Known Samples

MD5: c1b3cb436959507ecea9ab756916a627
SHA1: 9a2ad937d51c85b5e29121c14eedb10e10a7d7a4
SHA256: E0B5D1C90F385932AC5A9C2F62B4AE51663AC36F24382B48728A8C88F67D8F07
File Size: 1.56 MB, 1555968 bytes
MD5: 6f7d2ade454e54b5b9a7b2d500908b15
SHA1: 163336080d854d83203fb73edaf5aa9b8e4b9ac0
SHA256: 765BD0D1BA46DA4D04C560ECDAC0C0A1B8AB1DC9FD3665DE59BCED81CDB43712
File Size: 1.69 MB, 1694816 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 9.86.62.31
  • 4.8.0.0
Comments Steam Client Service
Company Name Valve Corporation
File Description Steam Client Service
File Version
  • 9.86.62.31
  • 4.8.0.0
Internal Name
  • Dcxpvnzhss.exe
  • steamservice.exe
Legal Copyright Copyright (C) Valve Corporation
Original Filename
  • Dcxpvnzhss.exe
  • steamservice.exe
Product Name Steam Client Service
Product Version
  • 9.86.62.31
  • 4.8.0.0

Digital Signatures

Signer Root Status
Valve Corp. DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 70
Potentially Malicious Blocks: 43
Whitelisted Blocks: 27
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 x x 0 x 0 0 x x 0 0 x 0 0 x 0 0 x x x x x x x x x 0 x 0 x x x 0 x x x x x x x x x 0 0 0 x 0 x x x x 0 0 x x x x x 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Mardom.BG

Files Modified

File Attributes
c:\users\user\appdata\roaming\cmdll.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\cmdll.vbs Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges

Related Posts

Trending

Most Viewed

Loading...