Trojan

TrojanDownloader:MSIL/ArtemisLoader.A!MTB removal instruction

Malware Removal

The TrojanDownloader:MSIL/ArtemisLoader.A!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:MSIL/ArtemisLoader.A!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine TrojanDownloader:MSIL/ArtemisLoader.A!MTB?


File Info:

name: ED96C90438F0C86B7E3F.mlw
path: /opt/CAPEv2/storage/binaries/3a1de46a83944f3c9c964113be0dabd38383cca6c42a0c84941cf25819d419cb
crc32: 0CC1B757
md5: ed96c90438f0c86b7e3f2a398280ad46
sha1: aabefcd9ee8c9d5381a33578472b96aaa3fe102f
sha256: 3a1de46a83944f3c9c964113be0dabd38383cca6c42a0c84941cf25819d419cb
sha512: e9af6ee62da21d7d5db951d003de6b5a4a559e83133a0e734af8bf5cf8b0abe838b6462d25b5384921fd640fb2ea4c781938c70e0120144c260a76d5da5d40cb
ssdeep: 384:FPDA9GPbbinE1ZCXIhSUaepk0OOyd3z0zYn:F89GPbbbCXESUaq1LyJQzU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111826C182391C767C47B8B3219F70B519BB8E27859374B1EE8D9123FCE433151A67B61
sha3_384: 61e2046db8a494e5b5102f3d0b3470fbc3e0d19d2d3e1a4a1cde54a53aaf3aa3955b7729c1919957653c9ade20e21ead
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-15 15:57:07

Version Info:

Translation: 0x0000 0x04b0
Comments: WhatsApp
CompanyName: WhatsApp
FileDescription: WhatsApp
FileVersion: 2.2210.9.0
InternalName: Rhnkjfqb.exe
LegalCopyright: Copyright © 2022 WhatsApp
LegalTrademarks:
OriginalFilename: Rhnkjfqb.exe
ProductName: WhatsApp
ProductVersion: 2.2210.9.0
Assembly Version: 2.2210.9.0

TrojanDownloader:MSIL/ArtemisLoader.A!MTB also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.21435
CAT-QuickHealTrojan.MSIL
SkyhighRDN/Generic Downloader.x
McAfeeRDN/Generic Downloader.x
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Bsymem.079126d2
K7GWTrojan-Downloader ( 0059459c1 )
K7AntiVirusTrojan-Downloader ( 0059459c1 )
BitDefenderThetaGen:NN.ZemsilCO.36802.bm0@aSu5HLc
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.MEM
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DDG24
KasperskyHEUR:Trojan.MSIL.Bsymem.gen
BitDefenderIL:Trojan.MSILZilla.21435
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-Downloader.Ader.Ngil
EmsisoftIL:Trojan.MSILZilla.21435 (B)
DrWebTrojan.DownLoaderNET.418
ZillyaDownloader.Agent.Win32.479444
TrendMicroTROJ_GEN.R002C0DDG24
FireEyeIL:Trojan.MSILZilla.21435
SophosTroj/DwnLd-AFV
IkarusTrojan-Downloader.MSIL.Agent
GDataIL:Trojan.MSILZilla.21435
JiangminTrojan.MSIL.amzzn
GoogleDetected
VaristW32/MSIL_Agent.DFP.gen!Eldorado
Antiy-AVLTrojan[Downloader]/MSIL.Agent
Kingsoftmalware.kb.c.983
ArcabitIL:Trojan.MSILZilla.D53BB
ViRobotTrojan.Win.Z.Agent.18944.KB
ZoneAlarmHEUR:Trojan.MSIL.Bsymem.gen
MicrosoftTrojanDownloader:MSIL/ArtemisLoader.A!MTB
AhnLab-V3Malware/Gen.Generic.C5006775
VBA32Downloader.MSIL.gen.rexp
ALYacIL:Trojan.MSILZilla.21435
MAXmalware (ai score=82)
MalwarebytesTrojan.Downloader.MSIL
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.94 (RDM.MSIL2:v5YjpXEtMmsiYQULwTkWSQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73722379.susgen
FortinetMSIL/Agent.MEW!tr.dldr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:MSIL/ArtemisLoader.A!MTB

How to remove TrojanDownloader:MSIL/ArtemisLoader.A!MTB?

TrojanDownloader:MSIL/ArtemisLoader.A!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment