Trojan

About “Trojan:Win32/FileCryptor.KA!MTB” infection

Malware Removal

The Trojan:Win32/FileCryptor.KA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FileCryptor.KA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/FileCryptor.KA!MTB?


File Info:

crc32: 1C94B13B
md5: e2b331c19cfad5ce2b6cdf02f321f6a1
name: E2B331C19CFAD5CE2B6CDF02F321F6A1.mlw
sha1: 83c85b89a43e57a2128a6934c5c0291dec5f0f37
sha256: e90a4923293492e330f79a858f980bf28529995df3b9ac31330de657d534318e
sha512: 885f822e7ca27dd9e43c6775ff67f65ba4560e520f7ab6ee8aa209e5182b853e088f1ae1705dd775f7bad826686930d5b31830e6259d00a3461b0e26882ee47c
ssdeep: 768:HzbCxOMGsHBnv2Yyn25ZSoujXZCLdD3bucQFsvLvh5D:HCcsHBv2nOZSo0ELdDrp6q5D
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Kampdommere2
FileVersion: 2.01
CompanyName: CC Pro 2019 xa9
Comments: CC Pro 2019 xa9
ProductName: CC Pro xa9
ProductVersion: 2.01
FileDescription: CC Pro xa9
OriginalFilename: Kampdommere2.exe

Trojan:Win32/FileCryptor.KA!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.77525
FireEyeGen:Variant.Midie.77525
CAT-QuickHealTrojan.Wacatac
McAfeePWS-FCTL!E2B331C19CFA
CylanceUnsafe
AegisLabTrojan.Win32.Midie.4!c
SangforMalware
BitDefenderGen:Variant.Midie.77525
K7GWTrojan ( 0057476e1 )
K7AntiVirusTrojan ( 0057476e1 )
CyrenW32/VBInject.AEQ.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9806459-0
KasperskyTrojan.Win32.Vebzenpak.acqp
AlibabaTrojan:Win32/Vebzenpak.71f356c4
RisingDownloader.Guloader!1.D025 (CLASSIC)
Ad-AwareGen:Variant.Midie.77525
EmsisoftGen:Variant.Midie.77525 (B)
ComodoMalware@#2rey1g9gqg5d7
F-SecureTrojan.TR/AD.VBCryptor.leqjg
DrWebTrojan.VbCrypt.1894
TrendMicroTROJ_GEN.R002C0PLE20
McAfee-GW-EditionPWS-FCTL!E2B331C19CFA
SophosMal/Generic-S
AviraTR/AD.VBCryptor.leqjg
MAXmalware (ai score=83)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/FileCryptor.KA!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Midie.D12ED5
ZoneAlarmTrojan.Win32.Vebzenpak.acqp
GDataGen:Variant.Midie.77525
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.FileCryptor.R358451
BitDefenderThetaGen:NN.ZevbaCO.34700.dm0@am2r9Npi
ALYacGen:Variant.Midie.77525
MalwarebytesTrojan.MalPack.VB.Generic
PandaTrj/GdSda.A
ZonerTrojan.Win32.99718
ESET-NOD32a variant of Win32/Injector.EOBU
TrendMicro-HouseCallTROJ_GEN.R002C0PLE20
YandexTrojan.Injector!Xhfnzn2ioMs
IkarusTrojan.VB.Crypt
eGambitUnsafe.AI_Score_98%
FortinetW32/EOBU!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Generic/Trojan.c16

How to remove Trojan:Win32/FileCryptor.KA!MTB?

Trojan:Win32/FileCryptor.KA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment