Trojan

TrojanDownloader:MSIL/AsyncRAT.CF!MTB malicious file

Malware Removal

The TrojanDownloader:MSIL/AsyncRAT.CF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:MSIL/AsyncRAT.CF!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine TrojanDownloader:MSIL/AsyncRAT.CF!MTB?


File Info:

name: 6F42E640B3FE08A55124.mlw
path: /opt/CAPEv2/storage/binaries/3f732809115a32f74dcd3822df79395eb76d734447ed47507e78cc58f996794c
crc32: 1DD3B9DE
md5: 6f42e640b3fe08a5512498524f0f11ab
sha1: 9eea5fb305fb984d598110bc4992bb291308acc0
sha256: 3f732809115a32f74dcd3822df79395eb76d734447ed47507e78cc58f996794c
sha512: bd434c45b0fc06bb7c0de348a283078be4958a4089ec428bf69340c45c7d2b3e1e5ba68fa378a50f1212a6f1f0ba382944a80de295414317a8be451a7f32ab9c
ssdeep: 192:uOaJeCid1bW7/UxBtC/IGmea/XZ80Kfx1vthNOPc5KFKjSDT7v4/C+Q3I7V0:uRM3bIUBn/TKZRthUk5KFKjqfvGBkS0
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17D626C636F6D9343EF568F3AA8E5D4036C3CBBC2CDDF665E204452161E0A3913B21A38
sha3_384: 7777081befe92f4f89847853c1e11a326047ed16e1a5889fb3b4945ad86b23d1e0e891431cfe786fc557ff4a9cb5edde
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-03-06 13:31:20

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: hmpdfldr
FileVersion: 23.3.6.29740
InternalName: hmpdfldr.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: hmpdfldr.exe
ProductName: hmpdfldr
ProductVersion: 23.3.6.29740
Assembly Version: 23.3.6.29740

TrojanDownloader:MSIL/AsyncRAT.CF!MTB also known as:

BkavW32.Common.18DFD869
LionicAdware.Win32.ConvertAd.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.26047
SkyhighArtemis!PUP
McAfeeArtemis!6F42E640B3FE
Cylanceunsafe
ZillyaAdware.ConvertAD.Win32.89465
K7GWTrojan ( 005a1d781 )
K7AntiVirusTrojan ( 005a1d781 )
VirITTrojan.Win32.Genus.QFL
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent_AGen.ARN
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.MSIL.ConvertAd.gen
BitDefenderIL:Trojan.MSILZilla.26047
NANO-AntivirusRiskware.Win32.AgentAGen.jzvrxi
AvastWin32:Adware-gen [Adw]
RisingTrojan.Agent!8.B1E (CLOUD)
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan.TR/Downloader.vbifp
VIPREIL:Trojan.MSILZilla.26047
TrendMicroTROJ_GEN.R002C0XEP23
EmsisoftIL:Trojan.MSILZilla.26047 (B)
IkarusTrojan.MSIL.Agent
JiangminAdWare.MSIL.odqj
WebrootW32.Malware.Gen
VaristW32/ABRisk.CHBW-2263
AviraTR/Downloader.vbifp
Antiy-AVLGrayWare[AdWare]/MSIL.ConvertAd
MicrosoftTrojanDownloader:MSIL/AsyncRAT.CF!MTB
ArcabitIL:Trojan.MSILZilla.D65BF
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.ConvertAd.gen
GDataIL:Trojan.MSILZilla.26047
GoogleDetected
ALYacIL:Trojan.MSILZilla.26047
MalwarebytesGeneric.Trojan.MSIL.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0XEP23
MaxSecureTrojan.Malware.74444617.susgen
FortinetMSIL/Agent.ARN!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:MSIL/AsyncRAT.CF!MTB?

TrojanDownloader:MSIL/AsyncRAT.CF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment