Trojan

Trojan:Win32/ICLoader.RPX!MTB removal instruction

Malware Removal

The Trojan:Win32/ICLoader.RPX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/ICLoader.RPX!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/ICLoader.RPX!MTB?


File Info:

name: 3BBB8B0BCC9A05803022.mlw
path: /opt/CAPEv2/storage/binaries/c4bb146d1d88f1683ee4a145fd1495bbc2fed8845a83a1a76c98d3a4bf332d80
crc32: ADA9EA0E
md5: 3bbb8b0bcc9a05803022674441a00e86
sha1: a01c1af624c08a2f464cdc45f04f94870c86ffcc
sha256: c4bb146d1d88f1683ee4a145fd1495bbc2fed8845a83a1a76c98d3a4bf332d80
sha512: 5abcefc9f18ce83c3d3e15e121b01fa6137314f66d03ca36c571c531e7ac374a1e815cde817446b62e9438a0389f541189df727b4353b81ffa59a1a7bfda431d
ssdeep: 98304:p5oCJriAVatRCRQuUBNCbnJUzcbgSYq+3wZ4MTwx3zXylE:2xYGJ6bnpsSn9TwBeu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10926333049F8C531E42A6E74AB1AC06A187BB89F3F7690DC93BC5E5DDB1D2A344017A7
sha3_384: 803069df3f1af55c5b8c2acaaa3e4b5ce2e1681f3896fdf3db222a875e47d5a67da2206f6ad93e742ae63e9c78033966
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-11-26 02:32:31

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: BusinessTV Setup
FileVersion:
LegalCopyright:
ProductName: BusinessTV
ProductVersion:
Translation: 0x0000 0x04b0

Trojan:Win32/ICLoader.RPX!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Injuke.16!c
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!3BBB8B0BCC9A
Cylanceunsafe
ZillyaTrojan.Injuke.Win32.37818
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Injuke.edc48fcf
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Agen-10015694-0
KasperskyTrojan.Win32.Injuke.jpuh
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Injuke.Yylw
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1332570
DrWebTrojan.Siggen22.18775
TrendMicroTROJ_GEN.R002C0DL723
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan.Ekstak.ciey
VaristW32/Trojan.XPNM-5448
AviraHEUR/AGEN.1332570
KingsoftWin32.Trojan.Injuke.jpuh
MicrosoftTrojan:Win32/ICLoader.RPX!MTB
ZoneAlarmTrojan.Win32.Injuke.jpuh
GDataWin32.Trojan.Agent.XQIAQU
AhnLab-V3Trojan/Win.DownloadAssistant.R621621
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002C0DL723
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/ICLoader.RPX!MTB?

Trojan:Win32/ICLoader.RPX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment