Trojan

About “Trojan:Win32/Downloader.RPE!MTB” infection

Malware Removal

The Trojan:Win32/Downloader.RPE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Downloader.RPE!MTB virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:Win32/Downloader.RPE!MTB?


File Info:

name: 0A4F7EB7C6804E457C03.mlw
path: /opt/CAPEv2/storage/binaries/04938d0c13e972cb89202c9ff012f43ec07742db2440b8b205bba0bfa2b427ba
crc32: AEE03F43
md5: 0a4f7eb7c6804e457c03fcd85898982c
sha1: 811a37bf91dc743ffad361c7c0f8f986925b339c
sha256: 04938d0c13e972cb89202c9ff012f43ec07742db2440b8b205bba0bfa2b427ba
sha512: b5e9376fb3da13e99ac619f86e8582487a3f3e4a5592b40f3bb8be6f722787c9a07f3a9a18fa412686cc0b2b901bbbc1f84741a863e4fdeeddf0635467ab52ac
ssdeep: 49152:IXnK017+DkGffGDoKKnsdllnK84ZvcyJZRCjh3liv8VOKYBA7Nm59pK:oK017+nsdllnK84ZvcymYBA7N698
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBE5E84EFAC450E1C9B784B918B31A4769B0DCEE0B0153C87DBD9056277DA69ECCD8B8
sha3_384: 3c8bfec4faff0cb68c3fb8af6647aac9ec1ad2c0d63c407f89235f946430827f45b71e2d7738196e231af9fafe90aece
ep_bytes: ff2500204000280029007b007d005b00
timestamp: 2020-01-30 01:29:13

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Skisploit
FileVersion: 2.0.2.0
InternalName: Skisploit.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: Skisploit.exe
ProductName: Skisploit
ProductVersion: 2.0.2.0
Assembly Version: 2.0.2.0

Trojan:Win32/Downloader.RPE!MTB also known as:

LionicTrojan.Win32.Perseus.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34020689
FireEyeGeneric.mg.0a4f7eb7c6804e45
McAfeeArtemis!0A4F7EB7C680
CylanceUnsafe
ZillyaTrojan.DllInject.Win32.3177
SangforTrojan.Win32.Occamy.C04
K7AntiVirusUnwanted-Program ( 00518a641 )
K7GWUnwanted-Program ( 00518a641 )
Cybereasonmalicious.7c6804
BitDefenderThetaGen:NN.ZemsilF.34114.!o0@auW7q4p
ESET-NOD32a variant of MSIL/DllInject.WV potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DA922
BitDefenderTrojan.GenericKD.34020689
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.34020689
EmsisoftTrojan.GenericKD.34020689 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DA922
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA IB (PUA)
IkarusPUA.MSIL.Dllinject
GDataTrojan.GenericKD.34020689
WebrootW32.Malware.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Occamy
GridinsoftRansom.Win32.Occamy.oa!s1
ArcabitTrojan.Generic.D2071D51
ViRobotTrojan.Win32.Z.Dllinject.3121664
APEXMalicious
MicrosoftTrojan:Win32/Downloader.RPE!MTB
ALYacTrojan.GenericKD.34020689
MalwarebytesMalware.AI.3334984174
YandexRiskware.Agent!mzbotwRFXKU
SentinelOneStatic AI – Suspicious PE
AVGWin32:Malware-gen
MaxSecureTrojan.Malware.74415778.susgen

How to remove Trojan:Win32/Downloader.RPE!MTB?

Trojan:Win32/Downloader.RPE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment