Crack

HackTool:Win32/AmDisable!MTB malicious file

Malware Removal

The HackTool:Win32/AmDisable!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/AmDisable!MTB virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine HackTool:Win32/AmDisable!MTB?


File Info:

crc32: B34781B0
md5: d142a4792297359c9c000d671abaac2b
name: D142A4792297359C9C000D671ABAAC2B.mlw
sha1: 9c5855a03ca328ec09a9ff3f16ea5bd7604b9afe
sha256: 4fd51972afad0f2b202359f4ff7626055f77d1f05eacb01b994035fffe88af5d
sha512: 34b8ddea1cb09b0b0733fab4ca565944dac835c1dc5c2d08009d235441adfaf28c55ce229c06bbd20a4b6be6494015f9db9b87ad7ceba2a530675437499dd7c5
ssdeep: 384:LYfKlWytNko+SRJajuV6BKFCzaWvjMfyZoAkYDistHWI:LYfjcNTajuVcKZsZncI
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: server-payload.ps1.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: server-payload.ps1.exe

HackTool:Win32/AmDisable!MTB also known as:

K7AntiVirusTrojan ( 00577cfc1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MSIL
ALYacGen:Variant.Bulz.199216
SangforTrojan.MSIL.Shelma.gen
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaHackTool:Win32/AmDisable.dd7e027e
K7GWTrojan ( 00577cfc1 )
Cybereasonmalicious.922973
CyrenW32/Trojan.QSQL-9248
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.UHC
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Shelma.gen
BitDefenderGen:Variant.Bulz.199216
MicroWorld-eScanGen:Variant.Bulz.199216
TencentMsil.Trojan.Shelma.Wofi
Ad-AwareGen:Variant.Bulz.199216
SophosMal/Generic-R + Mal/MSIL-KC
BitDefenderThetaGen:NN.ZemsilCO.34758.bm0@aOUiZvg
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RFF21
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.d142a4792297359c
EmsisoftGen:Variant.Bulz.199216 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Agent.wgxva
Antiy-AVLTrojan/Generic.ASMalwS.33903BD
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftHackTool:Win32/AmDisable!MTB
AegisLabTrojan.MSIL.Shelma.4!c
GDataGen:Variant.Bulz.199216
AhnLab-V3Trojan/Win32.Injector.R351243
McAfeeRDN/Generic PUP.z
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.3361796084
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0RFF21
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.73788019.susgen
FortinetW32/Shelma.KC!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove HackTool:Win32/AmDisable!MTB?

HackTool:Win32/AmDisable!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment