Trojan

Trojan:MSIL/DCRat.RDJ!MTB removal

Malware Removal

The Trojan:MSIL/DCRat.RDJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/DCRat.RDJ!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/DCRat.RDJ!MTB?


File Info:

name: 1542B4C66E595D476302.mlw
path: /opt/CAPEv2/storage/binaries/df6921fc0d3935daa42035c7f66620f3ea9c8ecb45f4af033d4b9c60927bf014
crc32: BC44A5E1
md5: 1542b4c66e595d4763026847af719741
sha1: c279e4df084cb631d8f26bed916498672ee75e63
sha256: df6921fc0d3935daa42035c7f66620f3ea9c8ecb45f4af033d4b9c60927bf014
sha512: 87b4088ad366bee604e1fe32186c8bd22c79988b3f83f8f94f836754ff42c0146510d66763d9099ddda5a62c7b1e323bdc17ad7371349e0ff79c3f42c50902dc
ssdeep: 49152:HcDwjbs1124u/f+99CWHrdyjY7dFAXTuQM+1Clq9RTMBj7uNDFGHcrhzL:Hcse24u/m99CWLd97GTvMcCYtVzrpL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA06E11565964F32C3A457728557823D42E1DB223A22FB1F3A1F20E36857BF18B762B3
sha3_384: b0df04e80266c9336f771a737868c1f3134cc71e7d17ecf733cb3343d1395d5d4a5663d008e6c03b38ce25aaade2f915
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-02-23 11:59:19

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.2.7.1277
InternalName: SpotifyStartupTask
LegalCopyright: Copyright (c) 2023, Spotify Ltd
OriginalFilename: SpotifyStartupTask.exe
ProductName:
ProductVersion: 1.2.7.1277
Translation: 0x0000 0x04b0

Trojan:MSIL/DCRat.RDJ!MTB also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.MSIL.Basic.8.Gen
ClamAVWin.Packed.Uztuby-10009381-0
FireEyeGeneric.mg.1542b4c66e595d47
SkyhighBehavesLike.Win32.Dropper.wc
McAfeeArtemis!1542B4C66E59
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.MSIL.Basic.8.Gen
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005ac5cb1 )
AlibabaTrojanPSW:MSIL/DCRat.12ac363e
K7GWTrojan ( 005ac5cb1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.ETF
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Disco.gen
BitDefenderTrojan.MSIL.Basic.8.Gen
AvastWin32:Evo-gen [Trj]
TencentMsil.Trojan-QQPass.QQRob.Kmnw
EmsisoftTrojan.MSIL.Basic.8.Gen (B)
F-SecureHeuristic.HEUR/AGEN.1323342
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.MSIL.Basic.8.Gen
GoogleDetected
AviraHEUR/AGEN.1323342
ArcabitTrojan.MSIL.Basic.8.Gen
ViRobotTrojan.Win.Z.Uztuby_10009381_0.3775488
ZoneAlarmHEUR:Trojan-PSW.MSIL.Disco.gen
MicrosoftTrojan:MSIL/DCRat.RDJ!MTB
VaristW32/MSIL_Kryptik.KIJ.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5493432
ALYacTrojan.MSIL.Basic.8.Gen
MAXmalware (ai score=89)
Cylanceunsafe
RisingTrojan.Dnoper!8.10CB3 (CLOUD)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.36744.Mp0@amNylDo
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.f084cb
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/DCRat.RDJ!MTB?

Trojan:MSIL/DCRat.RDJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment