Trojan

Trojan:MSIL/TrojanDropper.PSE!MTB information

Malware Removal

The Trojan:MSIL/TrojanDropper.PSE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/TrojanDropper.PSE!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:MSIL/TrojanDropper.PSE!MTB?


File Info:

name: E63F6311EAF2A6D619B3.mlw
path: /opt/CAPEv2/storage/binaries/4bab02fc5c443c3b1020fb076cd8b54f9a463dd62e9c2f4793c762afe5b281ac
crc32: 4107EC4B
md5: e63f6311eaf2a6d619b31a45233a3276
sha1: 37ec2fe74e823f4ba036ad1871a16411eaced196
sha256: 4bab02fc5c443c3b1020fb076cd8b54f9a463dd62e9c2f4793c762afe5b281ac
sha512: fc9b63d9a3d4b9ff5b78aa97583c0271110617351f44f6da9818aac1507d1bed8ae73d5ba732d39ca4c7213da91d6acb9ecbb1cc98a3b184a660e6f283abfbea
ssdeep: 98304:wMbnsqA/MbnsqA8bPk5HyUN8k5h/wDdEoNiV4I/hwAf1wAoTami9rsqAN:XbFb3bPk5HyC8k5h/wDdEoNiV4I/WWw5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA461910F5C384B1DFE38178A596F25FE721F18281249DEAF95C1A86AF336918D2F21D
sha3_384: 4e53442582ad3a6e8d534885bef45ad3fc53316a2b33d8d2380dea74f159aff6ffab1c4e71d6590d2d46ef953b90d4ad
ep_bytes: 6a706820144000e8f701000033db538b
timestamp: 2004-08-04 06:02:34

Version Info:

CompanyName: Microsoft Corporation
FileDescription: CTF Loader
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: CTFMON
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: CTFMON.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.2180
OleSelfRegister:
Translation: 0x0409 0x04b0

Trojan:MSIL/TrojanDropper.PSE!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agentb.X!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.393622
ClamAVWin.Malware.Generic-9839999-0
FireEyeGen:Variant.Bulz.393622
CAT-QuickHealTrojan.AgenFC.S20327787
McAfeeArtemis!E63F6311EAF2
CylanceUnsafe
VIPREGen:Variant.Bulz.393622
SangforTrojan.Win32.Save.a
AlibabaTrojan:MSIL/Redcap.a4f69e6f
Cybereasonmalicious.1eaf2a
CyrenW32/Olext.C.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FIF
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderGen:Variant.Bulz.393622
NANO-AntivirusTrojan.Win32.Memery.bybqne
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan.Agentb.Kqil
EmsisoftGen:Variant.Bulz.393622 (B)
DrWebWin32.Siggen.16
ZillyaDropper.Agent.Win32.468198
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.th
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1NNUGPB
AviraTR/Redcap.zojnv
MicrosoftTrojan:MSIL/TrojanDropper.PSE!MTB
GoogleDetected
Acronissuspicious
BitDefenderThetaAI:FileInfector.37DCC0A10D
ALYacWin32.Olext.A
MAXmalware (ai score=81)
MalwarebytesLamer.Virus.FileInfector.DDS
RisingDropper.Agent!8.2F (CLOUD)
YandexTrojan.Agent!AXRJ9YG7c6c
IkarusTrojan-Dropper.MSIL.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SPNR.15EG12!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan:MSIL/TrojanDropper.PSE!MTB?

Trojan:MSIL/TrojanDropper.PSE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment