Trojan

Trojan:Win32/CryptInject.DE!MTB removal tips

Malware Removal

The Trojan:Win32/CryptInject.DE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CryptInject.DE!MTB virus can do?

  • Unconventionial language used in binary resources: Arabic (Oman)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/CryptInject.DE!MTB?


File Info:

name: 8E8F2BE3077A382BD48B.mlw
path: /opt/CAPEv2/storage/binaries/b73d362a7b01ee5c88dfc1255e9bcc638c1956ad6165520f548a45fd31e90695
crc32: 35DAFB0A
md5: 8e8f2be3077a382bd48b02d3e92bb83f
sha1: 01cd2d98888006f4583e14f9f65c52b8479fabac
sha256: b73d362a7b01ee5c88dfc1255e9bcc638c1956ad6165520f548a45fd31e90695
sha512: 588946917b479109379de6d9d50cd22905251c9cc2ac134d6a31f7a4b3f45a5773332cecc118724feb90555bddc7ccc9e86f46cb6755cdf8923487df6ccf2fbd
ssdeep: 12288:IzFPm5cjJZFwz5ldLPhSSYDjesv0x1Icg:8PmLLPhShTMUN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEA45C81A94E417BFE73A332113CD5E28936A6716622685D53EC3C3EAF30D4CD764E29
sha3_384: ab724b3ba9be49da628d62e0691b4c1115e2486c6e2e717c3152190ed412a08c455196f09f715ca5ee52773db779cf4e
ep_bytes: e85b110000e9fb0b0000cccccccccccc
timestamp: 2017-05-06 22:44:50

Version Info:

0: [No Data]

Trojan:Win32/CryptInject.DE!MTB also known as:

BkavW32.AIDetectMalware
CyrenCloudW32/S-4ad12f59!Eldorado
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.11206
MicroWorld-eScanGen:Variant.Mikey.117444
ClamAVWin.Malware.Cerbu-7038950-0
FireEyeGeneric.mg.8e8f2be3077a382b
CAT-QuickHealBackdoor.Androm.A5
McAfeeTrojan-FMLV!8E8F2BE3077A
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.1145643
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0050cc221 )
AlibabaTrojan:Win32/Kryptik.8842bf29
K7GWTrojan ( 0050cc221 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.7EE5F5C11F
VirITTrojan.Win32.Encoder.QPA
CyrenW32/S-4ad12f59!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Kryptik.FSJS
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Worm.Win32.Oxynoxy.gen
BitDefenderGen:Variant.Mikey.117444
NANO-AntivirusTrojan.Win32.Kryptik.eoiann
SUPERAntiSpywareBackdoor.Bot/Variant
AvastWin32:Bzofiku-A [Drp]
TencentMalware.Win32.Gencirc.10b259dc
EmsisoftGen:Variant.Mikey.117444 (B)
VIPREGen:Variant.Mikey.117444
TrendMicroTROJ_LETHIC.SMT
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Mikey.117444
JiangminBackdoor.Androm.pbz
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1317714
Antiy-AVLTrojan/Win32.AGeneric
XcitiumBackdoor.Win32.Androm.AXQ@6yqacl
ArcabitTrojan.Mikey.D1CAC4
ViRobotTrojan.Win32.XPacker.Gen
ZoneAlarmHEUR:Worm.Win32.Oxynoxy.gen
MicrosoftTrojan:Win32/CryptInject.DE!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Scarsi.R200467
VBA32BScope.Trojan.Inject
ALYacGen:Variant.Mikey.117444
MAXmalware (ai score=83)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_LETHIC.SMT
RisingTrojan.Kryptik!1.AA6F (CLASSIC)
YandexTrojan.GenAsa!f9sLCgEBBqE
IkarusTrojan.Win32.Qadars
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ADEL!tr
AVGWin32:Bzofiku-A [Drp]
Cybereasonmalicious.3077a3
DeepInstinctMALICIOUS

How to remove Trojan:Win32/CryptInject.DE!MTB?

Trojan:Win32/CryptInject.DE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment