Categories: Backdoor

What is “Backdoor:Win64/Turla!MTB”?

The Backdoor:Win64/Turla!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win64/Turla!MTB virus can do?

    How to determine Backdoor:Win64/Turla!MTB?

    
    

    File Info:

    crc32: 70119224md5: 7ec8a9641d7342d1a471ebcd98e28b62name: 7EC8A9641D7342D1A471EBCD98E28B62.mlwsha1: 25cf8ebd4667b63df880e51744c98df51be374a1sha256: 915ad2650186cabd48befae7e195783e5b3bbdf38f0b4af9e0a9e73726779fa3sha512: c2ec921913f1823ca278f4bf7aa75517dd07e504e398cefd5eaa7117f5af624f2e0f3e72455fca370a5cb3084558108a56ead0602fa0270b50f9bd053092d4f2ssdeep: 3072:VI2CFKWMb/jgziQfYp8SU2CpDRJX9i9f3bFma1Hb:VIube2eX9i90adtype: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

    Version Info:

    LegalCopyright: Microsoft Corporation. All rights reserved.InternalName: WICACCESS.DLLFileVersion: 3.5.2.0CompanyName: Microsoft CorporationProductName: Microsoftxae Windowsxae Operating SystemProductVersion: 6.1.7601.17514FileDescription: Windows Integrity Control LibraryOriginalFilename: WICACCESS.DLLTranslation: 0x0409 0x04b0

    Backdoor:Win64/Turla!MTB also known as:

    Lionic Trojan.Win32.Turla.m!c
    Elastic malicious (high confidence)
    ALYac Backdoor.Turla.A
    Cylance Unsafe
    Zillya Backdoor.Turla.Win64.7
    Sangfor Backdoor.Win32.Turla.ghx
    CrowdStrike win/malicious_confidence_100% (W)
    Alibaba Backdoor:Win64/Turla.65ddaf00
    K7GW Trojan ( 005608111 )
    K7AntiVirus Trojan ( 005608111 )
    Symantec Trojan.Turla
    ESET-NOD32 a variant of Win64/Turla.BG
    Avast Win64:Trojan-gen
    Kaspersky Backdoor.Win32.Turla.ghx
    BitDefender Trojan.GenericKD.33281418
    NANO-Antivirus Trojan.Win64.Turla.hcukok
    MicroWorld-eScan Trojan.GenericKD.33281418
    Tencent Win32.Backdoor.Turla.Ammq
    Ad-Aware Trojan.GenericKD.33281418
    Sophos Mal/Generic-S
    Comodo Malware@#2oqk55n0th44t
    F-Secure Heuristic.HEUR/AGEN.1108423
    VIPRE Trojan.Win32.Generic!BT
    TrendMicro TROJ_GEN.R002C0DE121
    McAfee-GW-Edition Artemis!Trojan
    FireEye Trojan.GenericKD.33281418
    Emsisoft Trojan.GenericKD.33281418 (B)
    Jiangmin Backdoor.Turla.r
    Webroot W32.Trojan.Gen
    Avira HEUR/AGEN.1108423
    Antiy-AVL Trojan/Generic.ASMalwS.2FF52BF
    Microsoft Backdoor:Win64/Turla!MTB
    Arcabit Trojan.Generic.D1FBD58A
    ZoneAlarm Backdoor.Win32.Turla.ghx
    GData Trojan.GenericKD.33281418
    AhnLab-V3 Trojan/Win64.Turla.R346713
    McAfee Artemis!7EC8A9641D73
    MAX malware (ai score=85)
    VBA32 Backdoor.Turla
    Malwarebytes Malware.AI.1640013812
    Panda Trj/Turla.A
    TrendMicro-HouseCall TROJ_GEN.R002C0DE121
    Ikarus Trojan.Win64.Turla
    MaxSecure Trojan.Malware.6971530.susgen
    Fortinet W32/Turla.BG!tr.bdr
    AVG Win64:Trojan-gen
    Paloalto generic.ml
    Qihoo-360 Win32/Backdoor.TurlaOutlook.HggASOQA

    How to remove Backdoor:Win64/Turla!MTB?

    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.
    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Recent Posts

    What is “MSIL/TrojanDropper.Agent.BVT”?

    The MSIL/TrojanDropper.Agent.BVT is considered dangerous by lots of security experts. When this infection is active,…

    23 hours ago

    Should I remove “Generic.Dacic.94CCEEA9.A.A4A6DA47”?

    The Generic.Dacic.94CCEEA9.A.A4A6DA47 is considered dangerous by lots of security experts. When this infection is active,…

    23 hours ago

    Malware.AI.524217860 removal tips

    The Malware.AI.524217860 is considered dangerous by lots of security experts. When this infection is active,…

    1 day ago

    Trojan:Win32/Koutodoor.F removal tips

    The Trojan:Win32/Koutodoor.F is considered dangerous by lots of security experts. When this infection is active,…

    1 day ago

    How to remove “Malware.AI.1412460714”?

    The Malware.AI.1412460714 is considered dangerous by lots of security experts. When this infection is active,…

    1 day ago

    Generic.Dacic.8952383F.A.5EC8C34B removal instruction

    The Generic.Dacic.8952383F.A.5EC8C34B is considered dangerous by lots of security experts. When this infection is active,…

    1 day ago