Trojan

Should I remove “Trojan:Win32/Injector.RB!MTB”?

Malware Removal

The Trojan:Win32/Injector.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Injector.RB!MTB virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Injector.RB!MTB?


File Info:

crc32: 1D3D8F31
md5: e37f1204e4f348421fa0e4870134c742
name: uk25244221.exe
sha1: ae5522c509fa2acef6ef5e261aa96409bb4283ef
sha256: fb81dde8c089618ed263037c5b9346589777e6bb513166f62fb323164f7fdf8c
sha512: 381f726671ef42086cfccaa8d3428ec49a6ca68ad806a34344a39b898f147d7daef403c082912259435d232075c8d8cee78aac3de1198216ac890c5bcd15b444
ssdeep: 49152:vTlMo8dlyTh9x5YSum6MigYA+M178SJvFc/b3xjLNmQHT0y0snR4lGhpHbI17t9:vTlSUA6M3Nf0y018THs/KKRsovwrBNA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Injector.RB!MTB also known as:

MicroWorld-eScanGen:Variant.Zusy.303446
VBA32Trojan.Wacatac
FireEyeGeneric.mg.e37f1204e4f34842
ALYacGen:Variant.Zusy.303446
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Zusy.303446
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4e4f34
TrendMicroTROJ_GEN.R002C0DF720
SymantecML.Attribute.HighConfidence
AvastWin32:Malware-gen
GDataGen:Variant.Zusy.303446
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Injector.418baa3b
ViRobotTrojan.Win32.Z.Zusy.8319488
RisingTrojan.Generic!8.C3 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Zusy.303446 (B)
ComodoMalware@#1xfqkl4r5l2u
F-SecureTrojan.TR/Hijacker.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
SophosMal/Generic-S
IkarusVirus.Win32.DelfInject
AviraTR/Hijacker.Gen
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftTrojan:Win32/Injector.RB!MTB
ArcabitTrojan.Zusy.D4A156
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 85)
McAfeeArtemis!E37F1204E4F3
MAXmalware (ai score=86)
Ad-AwareGen:Variant.Zusy.303446
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DF720
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Ulise.1063!tr
BitDefenderThetaGen:NN.ZelphiF.34128.@JW@aSN8LgfQ
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/HEUR/QVM41.2.C2A5.Malware.Gen

How to remove Trojan:Win32/Injector.RB!MTB?

Trojan:Win32/Injector.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment