Trojan

What is “Trojan:Win32/CryptBot.ET!MTB”?

Malware Removal

The Trojan:Win32/CryptBot.ET!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CryptBot.ET!MTB virus can do?

  • Uses Windows utilities for basic functionality
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/CryptBot.ET!MTB?


File Info:

name: 0349120BF7AB458F924E.mlw
path: /opt/CAPEv2/storage/binaries/43552319fe32b8fe7f220edb83cacb78bc4aa8b6ed41692187c17f43623251d6
crc32: DC949366
md5: 0349120bf7ab458f924e335a6ad8a2d1
sha1: 2c81b4683ad4846c0dee0e2a4b9f1b6546f99793
sha256: 43552319fe32b8fe7f220edb83cacb78bc4aa8b6ed41692187c17f43623251d6
sha512: edcf4d11f3f00c8832bb66a7d23a5e8b24d91e2d46bf55bdff1d39a27af27a75e7af42f493bf7429e4d1b4b43ba06d1c33b652c573566212e5f6991edee84ec4
ssdeep: 384:Ol9oXvOznjcYER5QKkf49/4v737AX2hFrxRORmOyglHWUd76183u5rI:OLy2pE5Q+4T38qRORr1HW6788ArI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5D2E77AAA22C7B6C4A280B07916C37B94767F31316CA007F3D01F1625B89E5EA35F1D
sha3_384: 16fb616832a2cfee92261f0e0b41bf2d6107a9fab29fc9a0641f582d7642f14f0e834bee6eb40d691275a50cee676a2f
ep_bytes: 558bec6aff688041400068623c400064
timestamp: 2014-10-16 13:55:16

Version Info:

Comments:
CompanyName: 2
FileDescription:
FileVersion: 1, 0, 0, 1
InternalName:
LegalCopyright: Copyright ? 2013
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0409 0x04b0

Trojan:Win32/CryptBot.ET!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Fugrafa.40556
SkyhighPWSZbot-FAPH!0349120BF7AB
ALYacTrojan.Keylogger.Kivars
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Fugrafa.40556
SangforTrojan.Win32.Heuristic.ET
K7AntiVirusTrojan ( 0053380b1 )
BitDefenderGen:Variant.Fugrafa.40556
K7GWTrojan ( 0053380b1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36802.bq0@aOYq1sgb
SymantecBackdoor.Kivars
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.ZTG
APEXMalicious
KasperskyTrojan.Win32.Agentb.jzkd
AlibabaTrojan:Win32/CryptBot.33b33b42
NANO-AntivirusTrojan.Win32.BotFAPH.fqmcpx
AvastWin32:Evo-gen [Trj]
RisingTrojan.Cryptbot!8.113D9 (TFE:5:nARnw1m9IUI)
TACHYONTrojan/W32.ZBot.28672.B
EmsisoftGen:Variant.Fugrafa.40556 (B)
DrWebTrojan.Siggen7.809
ZillyaTrojan.Agent.Win32.1099907
TrendMicroTROJ_KIVARSDRP.ZTDG-AA
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.0349120bf7ab458f
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Fugrafa.40556
JiangminTrojan.Agentb.ivq
VaristW32/Zegost.AA.gen!Eldorado
Antiy-AVLTrojan/Win32.Blacktech
XcitiumMalware@#1ctiaggffoyq9
ArcabitTrojan.Fugrafa.D9E6C
ZoneAlarmTrojan.Win32.Agentb.jzkd
MicrosoftTrojan:Win32/CryptBot.ET!MTB
GoogleDetected
McAfeePWSZbot-FAPH!0349120BF7AB
MAXmalware (ai score=100)
VBA32BScope.Trojan.Dynamer
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_KIVARSDRP.ZTDG-AA
TencentWin32.Trojan.Agent.Crh
YandexTrojan.Graftor!jgssunhHvzY
IkarusTrojan.Win32.Agent
FortinetW32/KIVARSDRP_ZTDG.AA!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Trojan:Win32/CryptBot.ET!MTB?

Trojan:Win32/CryptBot.ET!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment