Trojan

Trojan:Win32/FileCryptor.MS!MTB information

Malware Removal

The Trojan:Win32/FileCryptor.MS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FileCryptor.MS!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

gxd3fp7fe7cac6jzn2sac.online

How to determine Trojan:Win32/FileCryptor.MS!MTB?


File Info:

crc32: 0D689E59
md5: 730dc7a54e38de9864c98a17d8c01006
name: 730DC7A54E38DE9864C98A17D8C01006.mlw
sha1: 0babab98481d16a9c38953d0f4e0a1a683c5f465
sha256: 68c9874dab6a9afe9e94bb238f4360743176fdf6661c98a6636a5fb5baa13f0f
sha512: 1046ebfcded4af81e813d650f1214e5b8a4194f02e6facb0dc9835c590c02ae30437196bef992bfe89185158a4e80f9f279e3f4db109f6f0f0655c064391cdf9
ssdeep: 6144:b4VdcXi9cFQDPKtjPTO0YrpSHolaZyJysyrW7Ejud8v76+hkRupqQzG3RwhTzFM:bliXLKtzYYHaaIJyPrW7Eq+T6nRaqQK
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationzi

Trojan:Win32/FileCryptor.MS!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45246706
ALYacTrojan.GenericKD.45246706
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0057569d1 )
BitDefenderTrojan.GenericKD.45246706
K7GWTrojan ( 0057569d1 )
Cybereasonmalicious.8481d1
BitDefenderThetaGen:NN.ZexaF.34700.xmGfaumXB4kc
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.SpyEyes.blbs
AlibabaTrojanSpy:Win32/SpyEyes.edc4396e
ViRobotTrojan.Win32.Z.Malpack.377344.A
TencentWin32.Trojan-spy.Spyeyes.Aduj
Ad-AwareTrojan.GenericKD.45246706
EmsisoftTrojan.Crypt (A)
ComodoMalware@#2ki72uu2r74pm
F-SecureTrojan.TR/Crypt.Agent.lnnfg
DrWebTrojan.DownLoader36.31721
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.730dc7a54e38de98
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.lnnfg
KingsoftWin32.Troj.SpyEyes.bl.(kcloud)
MicrosoftTrojan:Win32/FileCryptor.MS!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B268F2
ZoneAlarmTrojan-Spy.Win32.SpyEyes.blbs
GDataTrojan.GenericKD.45246706
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXAA-AA!730DC7A54E38
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.GS
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HIMF
RisingTrojan.Kryptik!8.8 (TFE:5:kqJznlF0rrH)
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_91%
FortinetW32/Kryptik.HGHW!tr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.43FD.Malware.Gen

How to remove Trojan:Win32/FileCryptor.MS!MTB?

Trojan:Win32/FileCryptor.MS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment