Trojan

How to remove “Trojan:Win32/Carbanak.MR!MTB”?

Malware Removal

The Trojan:Win32/Carbanak.MR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Carbanak.MR!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Carbanak.MR!MTB?


File Info:

name: 2828EA78CDDA8F211875.mlw
path: /opt/CAPEv2/storage/binaries/ce8ce35f85406cd7241c6cc402431445fa1b5a55c548cca2ea30eeb4a423b6f0
crc32: 3FBA0369
md5: 2828ea78cdda8f21187572c99ded6dc2
sha1: dccc5abd6ffc56ec0e54a3739b004bedfe8da09d
sha256: ce8ce35f85406cd7241c6cc402431445fa1b5a55c548cca2ea30eeb4a423b6f0
sha512: 3532dad44914ede08c8afd4ec1db63ce53434281a3fc8e8efe0a4bd5de5334df91d94fb7a89aa5b654666efe29bac01f517919ecf04fdbf6b665782dfbaa7cb1
ssdeep: 6144:tTB+2WIpTBq9jPs2jlgP6/HEu051DeyKsnC1o9:tLXTs9jPs2jlgPobgdeyj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16E44E092F191B0B1D5610A35A5DC5B3A9E3DBF212329D8F3E7D47811B9306D2D23A2CE
sha3_384: d5783ebfa200bd790473ffe43bf419ca5440c3e8ebb5f932ec4a332b1d75a628e5aeee53ce5ea68617566bb425cb415e
ep_bytes: 682400000068000000006830564400e8
timestamp: 2016-04-27 20:20:22

Version Info:

0: [No Data]

Trojan:Win32/Carbanak.MR!MTB also known as:

BkavW32.Common.F8B64411
LionicTrojan.Win32.Carbanak.l!c
MicroWorld-eScanGen:Variant.Jatif.2108
FireEyeGeneric.mg.2828ea78cdda8f21
SkyhighGenericRXDZ-EC!2828EA78CDDA
McAfeeGenericRXDZ-EC!2828EA78CDDA
Cylanceunsafe
ZillyaTrojan.SekurCRTD.Win32.8910
SangforSpyware.Win32.Carbanak.Vcd1
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanSpy:Win32/Carbanak.5f4e6044
K7GWSpyware ( 0055e3db1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Sekur.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Agent.deni
BitDefenderGen:Variant.Jatif.2108
NANO-AntivirusTrojan.Win32.Barys.edgzzf
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11bae277
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Agent.uxgqy
DrWebBackDoor.Anunak.114
VIPREGen:Variant.Jatif.2108
TrendMicroBKDR_CARBANAK.G
EmsisoftGen:Variant.Jatif.2108 (B)
GDataGen:Variant.Jatif.2108
JiangminTrojanSpy.Agent.aash
WebrootW32.Trojan.Gen
AviraTR/Spy.Agent.uxgqy
Antiy-AVLTrojan[APT]/Win32.Fin7
Kingsoftmalware.kb.a.997
ArcabitTrojan.Jatif.D83C
ViRobotTrojan.Win32.Z.Barys.276888
ZoneAlarmTrojan-Spy.Win32.Agent.deni
MicrosoftTrojan:Win32/Carbanak.MR!MTB
VaristW32/Agent.GIUR-6379
AhnLab-V3Spyware/Win.Agent.C5004947
ALYacBackdoor.Agent.Carbanak
MAXmalware (ai score=100)
VBA32TrojanSpy.Agent
MalwarebytesMalware.AI.3699440258
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_CARBANAK.G
RisingRansom.Locky!8.1CD4 (TFE:1:pinkGQVriZF)
YandexTrojanSpy.Sekur!Qt8FDg9ymA4
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.11871020.susgen
FortinetW32/Kryptik.FFVM!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Carbanak.MR!MTB?

Trojan:Win32/Carbanak.MR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment