Trojan

Trojan:Win32/Injector.INK!MTB removal

Malware Removal

The Trojan:Win32/Injector.INK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Injector.INK!MTB virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

sunray1975.zapto.org

How to determine Trojan:Win32/Injector.INK!MTB?


File Info:

crc32: 7844A60C
md5: 0286a708f47075b2c9a9f1f10f4d8205
name: 0286A708F47075B2C9A9F1F10F4D8205.mlw
sha1: 98e1ec890f706f77b66675e95d302feffe016c1b
sha256: 36721414ceb0b8581513e4889fa4c86f8ad75d7b7a8032e9b48885c5dbdfc34e
sha512: b743b64fd74a816ebf6e6d9c7bfc693ec179d6445212a692277d58181456d3e4c5611a0b50fe69c765d03ea6c8b5e710e284a20200659bea6a5ff5ba4f4a2d97
ssdeep: 196608:0Sazg7DS8Sazg7DS8Sazg7DS8Sazg7DS8Sazg7DSv:gg7uIg7uIg7uIg7uIg7uv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Injector.INK!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00548e051 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.7779
CynetMalicious (score: 100)
CAT-QuickHealTrojan.WacatacPMF.S16539689
ALYacGen:Variant.Symmi.34741
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 00548e051 )
Cybereasonmalicious.8f4707
CyrenW32/Injector.OZVT-2500
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AHHO
APEXMalicious
AvastWin32:MBRlock-DV [Trj]
ClamAVWin.Trojan.Mbrlock-9779766-0
KasperskyVHO:Backdoor.Win32.Androm.gen
BitDefenderGen:Variant.Symmi.34741
NANO-AntivirusTrojan.Win32.Dapato.bsjzfg
MicroWorld-eScanGen:Variant.Symmi.34741
TencentTrojan.Win32.Blocker.zg
Ad-AwareGen:Variant.Symmi.34741
SophosML/PE-A + Troj/Agent-BFYB
ComodoTrojWare.Win32.Injector.HO@82j6jo
BitDefenderThetaAI:Packer.9896AD8521
FireEyeGeneric.mg.0286a708f47075b2
EmsisoftGen:Variant.Symmi.34741 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.pkq
AviraDR/Delphi.Gen
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftTrojan:Win32/Injector.INK!MTB
ArcabitTrojan.Symmi.D87B5
GDataWin32.Trojan.PSE.4HB152
TACHYONBackdoor/W32.Androm.10396160
AhnLab-V3Dropper/Win32.Dapato.R83155
Acronissuspicious
McAfeeGenericRXIP-BJ!0286A708F470
MAXmalware (ai score=88)
VBA32Trojan.Downloader
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
RisingTrojan.Injector!1.DA56 (CLASSIC)
YandexTrojan.Injector!nfedw5apY3U
IkarusTrojan-Ransom.Blocker
FortinetW32/Injector.AHHO!tr
AVGWin32:MBRlock-DV [Trj]

How to remove Trojan:Win32/Injector.INK!MTB?

Trojan:Win32/Injector.INK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment