Trojan

What is “TrojanDownloader:Win32/Stealer.CK!MTB”?

Malware Removal

The TrojanDownloader:Win32/Stealer.CK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Stealer.CK!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Performs some HTTP requests
  • Looks up the external IP address
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.ipify.org
cussoricti.com

How to determine TrojanDownloader:Win32/Stealer.CK!MTB?


File Info:

crc32: 53158AC1
md5: 1db6bd4d13cb9966e8875b3812aef71d
name: 1DB6BD4D13CB9966E8875B3812AEF71D.mlw
sha1: 974c46a807d2d680dad5b6d63c38dd0e06e1ed68
sha256: 9bdbb8dde9ad9be8d9303df1697e13a0f846cca95bc9e41d513c1f5f2a7a37b3
sha512: 550405e7409846ab8673b6eacd1a8132d0582b3cde9360f92d812a9e399ac62459798839ae76e57144933fca2fbe36d89bf66fe72df668774eb5a2514a34ae4b
ssdeep: 6144:RQp4Potn6r86+hePn9VCqqNlFozawUDO/XwOt60v9a+:ip4K4n1221D
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Stealer.CK!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.41292
FireEyeGeneric.mg.1db6bd4d13cb9966
CAT-QuickHealTrojan.Zudochka
McAfeeGenericRXMH-DA!1DB6BD4D13CB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zudochka.4!c
SangforMalware
K7AntiVirusTrojan ( 0001555e1 )
BitDefenderGen:Variant.Jaik.41292
K7GWTrojan ( 0001555e1 )
Cybereasonmalicious.807d2d
TrendMicroTrojan.Win32.MALREP.THKOEBO
CyrenW32/Trojan.VFQM-0572
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Zudochka.vho
AlibabaTrojanDownloader:Win32/Stealer.cc771880
RisingTrojan.Agent!8.B1E (TFE:5:FdJXowScMLN)
Ad-AwareGen:Variant.Jaik.41292
SophosMal/Generic-S
F-SecureTrojan.TR/Agent.mrwul
DrWebTrojan.PWS.Siggen2.58564
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftGen:Variant.Jaik.41292 (B)
AviraTR/Agent.mrwul
MicrosoftTrojanDownloader:Win32/Stealer.CK!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Jaik.DA14C
ZoneAlarmHEUR:Trojan.Win32.Zudochka.vho
GDataGen:Variant.Jaik.41292
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R352614
BitDefenderThetaGen:NN.ZexaF.34590.qGX@aGpzdWh
ALYacTrojan.Agent.Zudochka
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesTrojan.Downloader
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Agent.UKB
TrendMicro-HouseCallTrojan.Win32.MALREP.THKOEBO
TencentWin32.Trojan.Zudochka.Ecbe
MAXmalware (ai score=100)
FortinetW32/Zudochka.UKB!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.22e

How to remove TrojanDownloader:Win32/Stealer.CK!MTB?

TrojanDownloader:Win32/Stealer.CK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment