Trojan

Trojan:Win32/Heodo.RPG!MTB removal instruction

Malware Removal

The Trojan:Win32/Heodo.RPG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Heodo.RPG!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Heodo.RPG!MTB?


File Info:

name: 25AE6DE78A68B02FAC76.mlw
path: /opt/CAPEv2/storage/binaries/160a45008b827171ed35360c57e72665db9273bbff4b122eea2f5e4dffe76535
crc32: ACF02335
md5: 25ae6de78a68b02fac76e67488dde29e
sha1: 702627fd6df0bd1b505a087e38746e0d44471d9d
sha256: 160a45008b827171ed35360c57e72665db9273bbff4b122eea2f5e4dffe76535
sha512: f825eaf191a7b417a8a5aa1515f93dd922b23edd371d34b5b33ce97101477491433d6dfc856ea754fb3f40d8722fc4337157aea533bbf7483d754f93a72e94fe
ssdeep: 3072:WRlAkeRZdn2hVE3YK3rOaN/o3AaeMphsTrcC7XPXdjt4EbHyrFcab5mxPGe0eGML:ElApHN3rOewhQ7/ltbb2qaVI+PHs
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D724E101B6E1E135D1BF023908BD89224B7D7D60EBB4C8AB7B89268E49742D07D35F63
sha3_384: 01c6945d70c1300b645802d0209eee04b7dda180d8f46e7a8540a4b2ccc6b00334df6905bd57eebc748d7c98f6fa07c7
ep_bytes: 558bec837d0c017505e80d310000ff75
timestamp: 2022-02-07 12:03:31

Version Info:

0: [No Data]

Trojan:Win32/Heodo.RPG!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.316034
FireEyeGeneric.mg.25ae6de78a68b02f
CAT-QuickHealTrojan.EmotetRI.S26566386
SkyhighBehavesLike.Win32.Emotet.dc
McAfeeEmotet-FTG!25AE6DE78A68
MalwarebytesTrojan.Emotet
VIPREGen:Variant.Barys.316034
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0058e1ac1 )
K7AntiVirusTrojan ( 0058e1ac1 )
ArcabitTrojan.Barys.D4D282
VirITTrojan.Win32.Emotet.DFW
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Emotet.CQ
ClamAVWin.Packed.Generic-9938674-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
BitDefenderGen:Variant.Barys.316034
NANO-AntivirusTrojan.Win32.Emotet.jmtqrw
AvastWin32:MalwareX-gen [Trj]
TACHYONBanker/W32.Emotet.218624.D
SophosTroj/Emotet-CYK
F-SecureHeuristic.HEUR/AGEN.1302819
DrWebTrojan.Emotet.1145
ZillyaTrojan.Emotet.Win32.62193
TrendMicroTROJ_GEN.R011C0DBQ24
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.316034 (B)
IkarusTrojan.Win32.Krypt
JiangminTrojan.Banker.Emotet.rct
GoogleDetected
AviraHEUR/AGEN.1302819
VaristW32/Emotet.EFI.gen!Eldorado
Antiy-AVLTrojan/Win32.Emotet
Kingsoftmalware.kb.a.983
MicrosoftTrojan:Win32/Heodo.RPG!MTB
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataGen:Variant.Barys.316034
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.EMOTET.C4958567
VBA32TrojanBanker.Emotet
ALYacTrojan.Agent.Emotet
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R011C0DBQ24
RisingTrojan.Kryptik!1.C71F (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Emotet.EIK!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Heodo.RPG!MTB?

Trojan:Win32/Heodo.RPG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment