Trojan

What is “Trojan:Win32/Libie.GNF!MTB”?

Malware Removal

The Trojan:Win32/Libie.GNF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Libie.GNF!MTB virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Trojan:Win32/Libie.GNF!MTB?


File Info:

name: 4B7CEF5BC203FB7D9AB9.mlw
path: /opt/CAPEv2/storage/binaries/0be1d6a6292fc586a19125c2ed58323128ef99be27117c9346af2142f02a82a4
crc32: 0032BCA9
md5: 4b7cef5bc203fb7d9ab94ccd506f4ed7
sha1: 72d44b521673372e4288e7c94657286025d6f613
sha256: 0be1d6a6292fc586a19125c2ed58323128ef99be27117c9346af2142f02a82a4
sha512: 19ff86afaa60601e7f780e162b4d34f794d2132df2c1cea7396755acb560fd07c19e859aef77afefcc5279e55981ee7a468fe62656bf5866f0ddf5719191d286
ssdeep: 49152:7io8aqE4Pg2/umxI78DYE4LwoX8U5MTk1pMeGqwMgSDosZTIdLCCrjTRDbv6FPhi:7iiqUzeYCRqLO1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127C57D32B391C437D0A35A3C8D1BA79C5835BE115E28A58B77E64F4C1F3AA80752D39B
sha3_384: 404fb7fd07b094750b5b80aa216fb565e1969bf35c6b2e595de57d8b62b295990e014963cfdf8f2aacf70436688be56c
ep_bytes: 558bec83c4f0b8f8a35c00e84ccae4ff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: WWW.RX88.NET
FileDescription:
FileVersion: 2.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 2.0.0.0
Comments:
Translation: 0x0804 0x03a8

Trojan:Win32/Libie.GNF!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.103499
SkyhighBehavesLike.Win32.Generic.vh
McAfeeGenericRXKJ-KU!4B7CEF5BC203
MalwarebytesMalware.AI.4118864283
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.216733
ArcabitTrojan.Generic.D1944B
VirITTrojan.Win32.Banker1.YTJ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanClicker.Libie_AGen.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.12765345-1
BitDefenderTrojan.GenericKDZ.103499
NANO-AntivirusTrojan.Win32.Banker1.dupial
TencentMalware.Win32.Gencirc.10b78676
DrWebTrojan.PWS.Banker1.16727
VIPRETrojan.GenericKDZ.103499
FireEyeGeneric.mg.4b7cef5bc203fb7d
EmsisoftTrojan.GenericKDZ.103499 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.gen
VaristW32/Clicker.X.gen!Eldorado
MAXmalware (ai score=80)
Antiy-AVLTrojan[Clicker]/Win32.Libie
MicrosoftTrojan:Win32/Libie.GNF!MTB
GDataWin32.Trojan.PSE.19SSP4K
GoogleDetected
VBA32TScope.Trojan.Delf
ALYacTrojan.GenericKDZ.103499
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.94 (RDML:NF67Dqni83E5OQvwH21BCQ)
YandexTrojan.GenAsa!Z96rrCNAbQI
IkarusTrojan-Clicker.Win32.Libie
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/LibieAGen.A!tr
BitDefenderThetaGen:NN.ZelphiF.36792.BM0@aGcEB2dj

How to remove Trojan:Win32/Libie.GNF!MTB?

Trojan:Win32/Libie.GNF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment