Trojan

Trojan.MTA.01056 removal instruction

Malware Removal

The Trojan.MTA.01056 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MTA.01056 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Trojan.MTA.01056?


File Info:

name: 972D43A53EDD86307EB4.mlw
path: /opt/CAPEv2/storage/binaries/08d139f342458c7c4db0ee716c6a2bf0897ae56eb92dcd7d3b5c3c0df164d3c3
crc32: 5A4B2005
md5: 972d43a53edd86307eb4660ac11b0330
sha1: 9136c3b682ebd9e10b3f66a965387a9756b7308a
sha256: 08d139f342458c7c4db0ee716c6a2bf0897ae56eb92dcd7d3b5c3c0df164d3c3
sha512: 59ea34aca00e0a1e26d37f0abf22db9800ac05f53ffbf71529d0ae95730e6dfe6f43e52d90fdaff02e613fd784f25bece2624c5e0d7e0b679fdfcdd98da2d4cf
ssdeep: 3072:nYAfxX3lz4WR6IM4lGTMEe4ZhOG8JlTv0rpl:nYgh1MbEkOGkzyp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12274D049B353C972C069413454CF8791AE39BE902D938BCA77C1BE2FAD36350E92726D
sha3_384: b43e0fc4d8fece2e247817790194eff7968aa5e40f7af37fc354c2df8f50e689d0fa69ca8d341f0b35b9f08fbfd9b497
ep_bytes: 558bec81c4e8feffff6a40eb03ff0c24
timestamp: 2003-05-05 06:01:50

Version Info:

0: [No Data]

Trojan.MTA.01056 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.28287
MicroWorld-eScanGen:Heur.VIZ.!e!.1
FireEyeGeneric.mg.972d43a53edd8630
CAT-QuickHealTrojan.Quolko.A
McAfeePWS-Zbot.gen.uz
CylanceUnsafe
ZillyaBackdoor.Shiz.Win32.4464
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Ramnit.bd3696ce
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.53edd8
BitDefenderThetaGen:NN.ZexaF.34212.vmW@aSiY6zhc
VirITTrojan.Win32.Generic.AWXZ
CyrenW32/Bamital.I
SymantecTrojan.Bamital
ESET-NOD32Win32/Virut.NBP
TrendMicro-HouseCallTROJ_BAMITAL.SML
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-7584013-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.VIZ.!e!.1
NANO-AntivirusTrojan.Win32.Kryptik.bstyem
AvastWin32:Trojan-gen
TencentVirus.Win32.Virut.ua
Ad-AwareGen:Heur.VIZ.!e!.1
EmsisoftGen:Heur.VIZ.!e!.1 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
BaiduWin32.Virus.Virut.gen
VIPRETrojan.Win32.Agent.ie (v)
TrendMicroTROJ_BAMITAL.SML
McAfee-GW-EditionBehavesLike.Win32.Swisyn.fz
SophosMal/Generic-S
IkarusTrojan-Ransom.PornoBlocker
GDataGen:Heur.VIZ.!e!.1
JiangminWin32/Virut.bv
eGambitGeneric.Downloader
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.1A5CD6
KingsoftHeur.SSC.2698478.1216.(kcloud)
ArcabitTrojan.VIZ.!e!.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ramnit.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FraudPack.R3415
Acronissuspicious
VBA32Trojan.MTA.01056
ALYacGen:Heur.VIZ.!e!.1
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingVirus.Virut!8.44 (CLOUD)
YandexTrojan.GenAsa!tYsvsBIAEGo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Qbot.AEM!tr
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.MTA.01056?

Trojan.MTA.01056 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment