Trojan

Should I remove “Trojan:Win32/Downloader.CAE!MTB”?

Malware Removal

The Trojan:Win32/Downloader.CAE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Downloader.CAE!MTB virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Downloader.CAE!MTB?


File Info:

name: D54C004CBEB126CB29B5.mlw
path: /opt/CAPEv2/storage/binaries/bb804c8dffe817b776523e358f8a76d0d40254d32fafa2c744762cf06431b2d6
crc32: FA2B83AD
md5: d54c004cbeb126cb29b5e738724e5a91
sha1: 45ef5a17639c4d447d026c543ab98da20ac1104d
sha256: bb804c8dffe817b776523e358f8a76d0d40254d32fafa2c744762cf06431b2d6
sha512: 3cad2e7004a40b52a09e76856476686c8feef519f62851de39ef6bdb8475817130562f6dbf57b7b5682bb83cd8955df38dd9fcc9ded8d258d0b3928b4bc27489
ssdeep: 49152:ARqXIger7S85/2N3fYLf2089XJwsjukddpjzxx+FoqPPRP4C6:ARqX4Se/k3AL45Jw6ukdPjlcFvPRP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8A5335B232CE5EBC32B587461D1CE7A1D641FE8C417697D2288CC984F94EA32F6B532
sha3_384: 801ac144bca650b304594f2f561de97e262913d9bc671e99099e98a5dd333b4658ad50b1c7ed1927863e4ff1dc486887
ep_bytes: eb08001012000000000060e800000000
timestamp: 2012-06-26 10:32:30

Version Info:

Comments:
CompanyName: 金山软件股份有限公司
FileDescription: JxOnline Client
FileVersion: 3, 0, 0, 6
InternalName: Game
LegalCopyright: 版权所有 (C) 1995-2004 金山软件股份有限公司
LegalTrademarks:
OLESelfRegister:
OriginalFilename: Game.exe
PrivateBuild:
ProductName: SwordOnline
ProductVersion: 3.00.00.2003
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan:Win32/Downloader.CAE!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!D54C004CBEB1
CylanceUnsafe
K7AntiVirusTrojan ( 005203381 )
AlibabaTrojan:Win32/EnigmaProtector.dd494929
K7GWTrojan ( 005203381 )
CrowdStrikewin/malicious_confidence_80% (W)
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.M suspicious
APEXMalicious
BitDefenderTrojan.GenericKD.38136913
MicroWorld-eScanTrojan.GenericKD.38136913
AvastFileRepMetagen [Malware]
Ad-AwareTrojan.GenericKD.38136913
EmsisoftTrojan.GenericKD.38136913 (B)
FireEyeGeneric.mg.d54c004cbeb126cb
SophosGeneric ML PUA (PUA)
IkarusPUA.EnigmaProtector
GDataTrojan.GenericKD.38136913
AviraHEUR/AGEN.1136095
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D245EC51
MicrosoftTrojan:Win32/Downloader.CAE!MTB
BitDefenderThetaGen:NN.ZexaF.34062.fI0@aSFk@4oj
ALYacTrojan.GenericKD.38136913
VBA32Trojan.Wacatac
TrendMicro-HouseCallTROJ_GEN.R002H01KS21
YandexTrojan.GenAsa!uWMNeO8FMZs
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_68%
FortinetRiskware/Application
AVGFileRepMetagen [Malware]
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Downloader.CAE!MTB?

Trojan:Win32/Downloader.CAE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment