Crack

HackTool:Win32/Crack!MTB information

Malware Removal

The HackTool:Win32/Crack!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/Crack!MTB virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Deletes executed files from disk
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine HackTool:Win32/Crack!MTB?


File Info:

name: 8363B38EAB70B1A73611.mlw
path: /opt/CAPEv2/storage/binaries/fc28702cdb406679eeb7e70e58554b12879daf0a7036c9be241e22b9daf1a055
crc32: 679A656F
md5: 8363b38eab70b1a73611fb7486fda15b
sha1: a645c0e541248eb9db55da6445c5a223404c915c
sha256: fc28702cdb406679eeb7e70e58554b12879daf0a7036c9be241e22b9daf1a055
sha512: bca4baf3edeb7125e5d583efba695fe95ebbef84d4c14fc327c504f156fc2b2b365a62b6469ac9069ea19b9f6533f603bd971b805783a7824521ad86c28ce2c7
ssdeep: 98304:c2yEkw7GTWibXBRRVeKguh4PW4VK0l49jtsoDb6WMQbHHSmDtp2AA1U+zus6Y4SD:c8kEGTW+3RJxuLqn9qLHmz2xU+zujbZ8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104763337DA4BD071CEFADEB10E3F71E222312DA048C6C342FC718687A996556D58276B
sha3_384: dec815313378151ab54ab29c208a88a9ea58696b6ded7296581821a9b0705218c4f64506f1c9984b8582375c1af80efb
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:19:59

Version Info:

Comments:
CompanyName: Tonek Inc.
FileDescription: Internet Download Manager v6.35.18
FileVersion: 6.35.18.3
LegalCopyright: © Tonek Inc.
ProductName: Internet Download Manager v6.35.18
Translation: 0x0000 0x04b0

HackTool:Win32/Crack!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Witch.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.37492151
ALYacTrojan.GenericKD.37492151
SangforPUP.Win32.Agent.Vw3x
ArcabitTrojan.Generic.D23C15B7
SymantecML.Attribute.HighConfidence
Kasperskynot-a-virus:HEUR:AdWare.NSIS.AdPack.gen
BitDefenderTrojan.GenericKD.37492151
AvastWin32:Malware-gen
RisingTrojan.Generic@AI.85 (RDMK:wi/9yeP8XuU14wX1Aky+nA)
EmsisoftTrojan.GenericKD.37492151 (B)
F-SecureTrojan.TR/Redcap.aaukf
DrWebTrojan.DownLoader26.21166
VIPRETrojan.GenericKD.37492151
TrendMicroPUA.Win32.IDMan.A
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
FireEyeTrojan.GenericKD.37492151
SophosGeneric Reputation PUA (PUA)
AviraTR/Redcap.aaukf
XcitiumApplicUnwnt@#39ef6ah68wpk4
MicrosoftHackTool:Win32/Crack!MTB
ZoneAlarmnot-a-virus:HEUR:AdWare.NSIS.AdPack.gen
GDataTrojan.GenericKD.37492151
CynetMalicious (score: 100)
VBA32Trojan.Witch
Cylanceunsafe
TrendMicro-HouseCallPUA.Win32.IDMan.A
MaxSecureTrojan.Malware.108792242.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (W)

How to remove HackTool:Win32/Crack!MTB?

HackTool:Win32/Crack!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment