Trojan

Should I remove “Trojan:Win32/Addrop!MTB”?

Malware Removal

The Trojan:Win32/Addrop!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Addrop!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk

How to determine Trojan:Win32/Addrop!MTB?


File Info:

name: 180BFE14E0FB0595A20B.mlw
path: /opt/CAPEv2/storage/binaries/b776233a159a1a8b2aa431edbb5dfaae804cf6dab2a84310f2f272295944e6f9
crc32: 4EDCECFF
md5: 180bfe14e0fb0595a20b2d82d7e5e9a4
sha1: 60f5c875c48412c4fbe49eba8fbf1c0e7c615d08
sha256: b776233a159a1a8b2aa431edbb5dfaae804cf6dab2a84310f2f272295944e6f9
sha512: 788215e4fd569d1bfdc9df7158c1a533bb26eca3f4491f20295a13367a12fe3f86df34be1f642e431d86c38319cc34b5a4eb2cc31f9e6341d3fc93abf0dce11b
ssdeep: 12288:uaHc64b888888888888W88888888888+oscV7/9GqeMo3HM5oUQo33rD+zG/oBiC:F867jW7/9oHTJ2ezG/aYFkJR30F6rp8q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6F41213B3C30071F5215A35CC76C044AD2779B949F0606A2EF9EB0E4EBA6C69D7BB61
sha3_384: 853b41b1453c36afd0eedd93a78ed36899b8aec1eeface5593431426a16f9d68e83adbc66ae2e778556f667e51a32ce3
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2018-06-14 13:27:46

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion: 134.206
LegalCopyright:
ProductName:
ProductVersion: 134.206
Translation: 0x0000 0x04b0

Trojan:Win32/Addrop!MTB also known as:

LionicTrojan.Win32.MalCrack.4!c
DrWebAdware.OxyPumper.18
MicroWorld-eScanGeneric.Addrop.A.273ED63A
FireEyeGeneric.Addrop.A.273ED63A
ALYacGeneric.Addrop.A.273ED63A
MalwarebytesAddrop.Trojan.Dropper.DDS
VIPREGeneric.Addrop.A.273ED63A
SangforDropper.Win32.Addrop.Vfy0
K7AntiVirusTrojan ( 0053aeb31 )
BitDefenderGeneric.Addrop.A.273ED63A
K7GWTrojan ( 0053aeb31 )
Cybereasonmalicious.4e0fb0
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Addrop.CH
APEXMalicious
ClamAVWin.Malware.Ejfb-9784212-0
KasperskyTrojan.Win32.MalCrack.a
AlibabaTrojanDropper:Win32/MalCrack.3c039b2a
RisingDownloader.TaskLoader/ARCHIVE!1.CDEA (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen8
TrendMicroTROJ_GEN.R002C0DCG23
McAfee-GW-EditionBehavesLike.Win32.Dropper.bc
EmsisoftGeneric.Addrop.A.273ED63A (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Agentino.a
AviraTR/Crypt.XPACK.Gen8
MicrosoftTrojan:Win32/Addrop!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmTrojan.Win32.MalCrack.a
GDataGeneric.Addrop.A.273ED63A
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5380804
Acronissuspicious
McAfeeArtemis!180BFE14E0FB
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DCG23
TencentTrojan.Win32.MalCrack.haw
YandexTrojan.DR.Addrop!Y5mNkjfMmOU
IkarusTrojan-Dropper.Addrop
FortinetW32/Addrop.CH!tr
AVGNSIS:Adware-AEQ [Adw]
AvastNSIS:Adware-AEQ [Adw]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Addrop!MTB?

Trojan:Win32/Addrop!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment