Trojan

Trojan:Win32/Masslogger.VB!MTB removal

Malware Removal

The Trojan:Win32/Masslogger.VB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Masslogger.VB!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Masslogger.VB!MTB?


File Info:

crc32: 0492BDA5
md5: e0a661eac3446ead101d8f111cf92cef
name: FAX-Zahlung 307144_2020-03-09_DE_E-INVOICE_20-613129926-11.exe
sha1: e8ff8571070b81775a2ac018fe1efcb8880815c3
sha256: 81337231c53d0927b5aaff1792d71b5f5270e268e1909267ad3bd79951e72642
sha512: 2a6f1a1e02caef77cec32cb494d655e4876dfb5395a7fe3287e9d56421e6b47eb21770df65dfae41e6e3549b0e65d28e35cd7dc47ff3fb65c29cdede603ac071
ssdeep: 6144:hc+MZ5vUJdn+gmRXrxdOHZojz4nWDTTq6mP8nbPhhaC2oxzzH+oLurr8:hc+MsCNdOHZrWX+6mP8DhYeVzl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0407 0x04b0
ProductVersion: 142.17.0777
InternalName: 76d5edur6t78u97rtzu
FileVersion: 142.17.0777
OriginalFilename: 76d5edur6t78u97rtzu.exe
ProductName: TheGreatAwakening

Trojan:Win32/Masslogger.VB!MTB also known as:

BkavHW32.Packed.
DrWebTrojan.DownLoader33.55222
MicroWorld-eScanGen:Variant.Razy.693402
FireEyeGeneric.mg.e0a661eac3446ead
CAT-QuickHealTrojan.Multi
ALYacGen:Variant.Razy.693402
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0056808e1 )
BitDefenderGen:Variant.Razy.693402
K7GWTrojan ( 0056808e1 )
Cybereasonmalicious.ac3446
TrendMicroTROJ_GEN.R002C0PFH20
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Razy.693402
KasperskyTrojan-PSW.Win32.Azorult.aodm
AlibabaTrojanPSW:Win32/Azorult.c6e0c377
TencentWin32.Trojan.Crypt.Ajbi
Ad-AwareGen:Variant.Razy.693402
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen3
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.693402 (B)
IkarusTrojan.Win32.Krypt
JiangminTrojan/Obfuscated.Gen
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan[PSW]/Win32.Azorult
MicrosoftTrojan:Win32/Masslogger.VB!MTB
ArcabitTrojan.Razy.DA949A
ZoneAlarmTrojan-PSW.Win32.Azorult.aodm
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Kryptik.R340936
McAfeeFareit-FST!E0A661EAC344
MAXmalware (ai score=85)
MalwarebytesSpyware.MassLogger.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EMKM
TrendMicro-HouseCallTROJ_GEN.R002C0PFH20
RisingTrojan.Injector!1.C6AF (CLOUD)
YandexTrojan.GenKryptik!
FortinetW32/GenKryptik.ELSW!tr
WebrootW32.Trojan.Gen
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.PSW.be9

How to remove Trojan:Win32/Masslogger.VB!MTB?

Trojan:Win32/Masslogger.VB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment