Trojan

Trojan:Win32/InjectorCrypt.SN!MTB removal

Malware Removal

The Trojan:Win32/InjectorCrypt.SN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/InjectorCrypt.SN!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

cutit.org
q.gs
usfinf.net

How to determine Trojan:Win32/InjectorCrypt.SN!MTB?


File Info:

crc32: B330048E
md5: 98eb0df6078a00030963ad2e6b88df2a
name: 98EB0DF6078A00030963AD2E6B88DF2A.mlw
sha1: 6c8b4911c0888a2e8a8254ed4ecacd99ca7162d6
sha256: 13d7d7d96e945eaa9e1fe18bbb4e5e748a5b4fad20099c25bffc98f3436d78ef
sha512: 45e4c55efb8807c23191411f898541dedfcd257113c6f3598c7c80bc7c14cdfb23b459f4104f97a917bfd7e3a6093b49b3ad7b7e6359698b763c5cc479359ac9
ssdeep: 3072:QHfW7g8kZ6kJI8FnwMCShGHvM3X5lStRQ:Qeu6kJDFnNB4vUz4RQ
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan:Win32/InjectorCrypt.SN!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057cf3b1 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.imW@!hBy@@e
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
K7GWTrojan ( 0057cf3b1 )
Cybereasonmalicious.6078a0
CyrenW32/Kryptik.DZR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Trojan.Heur.imW@!hBy@@e
MicroWorld-eScanGen:Trojan.Heur.imW@!hBy@@e
Ad-AwareGen:Trojan.Heur.imW@!hBy@@e
SophosMal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.335106D81B
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.98eb0df6078a0003
EmsisoftGen:Trojan.Heur.imW@!hBy@@e (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_91%
Antiy-AVLTrojan/Generic.ASCommon.1FB
MicrosoftTrojan:Win32/InjectorCrypt.SN!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Trojan.Heur.imW@!hBy@@e
AhnLab-V3Malware/Win32.Generic.C2860595
McAfeeGenericRXAA-FA!98EB0DF6078A
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D238 (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:Trojan-gen

How to remove Trojan:Win32/InjectorCrypt.SN!MTB?

Trojan:Win32/InjectorCrypt.SN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment