Trojan

How to remove “Trojan.Win32.Matanbuchus.du”?

Malware Removal

The Trojan.Win32.Matanbuchus.du is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Matanbuchus.du virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the Alfonoso malware family

How to determine Trojan.Win32.Matanbuchus.du?


File Info:

name: 3C1E0C4A5DE8B97EB217.mlw
path: /opt/CAPEv2/storage/binaries/27e939d82970bdb04f6ff714721c17b8c243679ced6581476fc7c369caa00e89
crc32: 0DB89FED
md5: 3c1e0c4a5de8b97eb21736eb92608a33
sha1: ffbed6ba3643b42c9cf30287b7c35b93c4452539
sha256: 27e939d82970bdb04f6ff714721c17b8c243679ced6581476fc7c369caa00e89
sha512: ebcda7692d61e14c8df492c22d756ead040b81314a0cd7baf1384f3e68c9d15156b3b7f69b8da2c90bbea60a14d8a2afab50ffd17337210a7f311fc12e77d159
ssdeep: 98304:TEesNq9x4ACcO5xs1cS7bgH9zAw12jqwZYSx5k4u2U6cxJBOslQWjTlTCdeIer:AesNpAaxs1cS7bIGm2ZuR4hCLN2WjTlf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1594623A762391041E1D98D3AE637FED572F713278B81F97C60D66CC12A629E5E203D83
sha3_384: 68e64d9402314bc847c6d81f361783740c9a57e5053d12b8f1acaf88f9799cf6625cdc12ab63ed3dc33b401e471b3ad6
ep_bytes: 686725c58de8c9b5b9ff48e95d41f4ff
timestamp: 2021-11-19 13:33:03

Version Info:

0: [No Data]

Trojan.Win32.Matanbuchus.du also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.3c1e0c4a5de8b97e
McAfeeArtemis!3C1E0C4A5DE8
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
AlibabaTrojan:Win32/Matanbuchus.47526607
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.a3643b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.ZP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Matanbuchus.du
AvastWin32:Trojan-gen
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/VMProtBad-A
IkarusTrojan.Win32.VMProtect
GDataWin32.Trojan-Stealer.PSWSteal.WYLF8Q
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1138342
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Tnega!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R456229
BitDefenderThetaGen:NN.ZexaF.34062.@FW@a8mgzboi
MalwarebytesSpyware.PasswordStealer.VMP
RisingMalware.Heuristic!ET#88% (RDMK:cmRtazrZd2PIQDCyq+2wafkJSCD0)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win32.Matanbuchus.du?

Trojan.Win32.Matanbuchus.du removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment