Trojan

Trojan:Win32/Cryptinject.MX!MTB removal guide

Malware Removal

The Trojan:Win32/Cryptinject.MX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cryptinject.MX!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Mongolian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Attempts to stop active services
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Cryptinject.MX!MTB?


File Info:

crc32: 60E4A61C
md5: a9b2d75be23f8feeeabf6c58430e22e5
name: A9B2D75BE23F8FEEEABF6C58430E22E5.mlw
sha1: 0d8bfbcbd26b4fecf73503909a82dc9ba0d0e278
sha256: 8e115ba551c4136d179d3264d65ea236a9787fb2fcbc11441a03d31785632f52
sha512: 88ab10d9ef37ef9041bcce1bb3e737657ec95cd8c154493c1bf8dee4dc94c0bd274cd868df62a1d33ea725df1e81754d7a6b93176dc6562916ee6621cabd7494
ssdeep: 3072:1q8+l+i0JZuVu9hufH07XAi6G9d7SFzmP1VKO4hum0S1out12q8WpLI8eTV2:QAZQu98fH07wk9AdmDYR08oSwqt6dTE
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan:Win32/Cryptinject.MX!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056750d1 )
LionicTrojan.Win32.Ursu.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.878862
CylanceUnsafe
ZillyaTrojan.Sodin.Win32.12
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Sodin.c35a2163
K7GWTrojan ( 0056750d1 )
Cybereasonmalicious.be23f8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HDOT
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Eb.vho
BitDefenderGen:Variant.Ursu.878862
NANO-AntivirusTrojan.Win32.Eb.ituqtw
MicroWorld-eScanGen:Variant.Ursu.878862
TencentWin32.Trojan.Sodin.Lpbe
Ad-AwareGen:Variant.Ursu.878862
SophosMal/Generic-S + Troj/Agent-BFFP
BitDefenderThetaGen:NN.ZexaF.34236.nmIfaKacSPaG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGen:Variant.Ursu.878862
EmsisoftGen:Variant.Ursu.878862 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.wtmwv
Antiy-AVLTrojan/Generic.ASMalwS.309343F
MicrosoftTrojan:Win32/Cryptinject.MX!MTB
GDataGen:Variant.Ursu.878862
AhnLab-V3Malware/Win32.Generic.C4145466
McAfeeArtemis!A9B2D75BE23F
MAXmalware (ai score=85)
VBA32TrojanRansom.Sodin
PandaTrj/CI.A
IkarusTrojan.Win32.Krypt
FortinetW32/CoinMiner.HPDF!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Cryptinject.MX!MTB?

Trojan:Win32/Cryptinject.MX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment