Trojan

Should I remove “Trojan:Win32/Pikabot.IP!MTB”?

Malware Removal

The Trojan:Win32/Pikabot.IP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Pikabot.IP!MTB virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Pikabot.IP!MTB?


File Info:

name: E2313819CD42B6FE1B47.mlw
path: /opt/CAPEv2/storage/binaries/51e96b061c4f119b3e0ffa9cc1620924fd2e04ca69dfe3ce5a582c310bc62d2d
crc32: 2D928E5C
md5: e2313819cd42b6fe1b47144d0696cade
sha1: 19c3e2de3531a26cb591938f50176645527e8008
sha256: 51e96b061c4f119b3e0ffa9cc1620924fd2e04ca69dfe3ce5a582c310bc62d2d
sha512: 753a89a703f5ef417afb54188697ce202a7c9c0ba4352e67f61a63c0acbbbed52528af859cdfbd5026eb2fac18889248d047bbfcfb845d323e066b6c14626e6a
ssdeep: 49152:f7TvfU+8X9GrNOsva0RShB3ANkTTlUk0l+yz5LDd6OzSfEBcWiWY7HPF:0+8X9G3vc3AM50ZHSsBDiWYTF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196D5C070F9128637E67346B78DBE3A2E892C73B2572350C791541D5A19B22D2BF3620F
sha3_384: ada0f265795054bf957357304e6a91c7cef617c4c332421404626fcfe1a873d66fee651765ead8772e5c911ce5e0220e
ep_bytes: 90909090909090909090909090909090
timestamp: 1970-01-01 11:21:26

Version Info:

0: [No Data]

Trojan:Win32/Pikabot.IP!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Dacic.9B39DA2A.A.982A88E9
CAT-QuickHealTrojan.Skeeyah.14991
SkyhighBehavesLike.Win32.Generic.vm
McAfeeGenericRXLJ-AF!E2313819CD42
MalwarebytesGeneric.Malware.AI.DDS
VIPREDeepScan:Generic.Dacic.9B39DA2A.A.982A88E9
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005ad28d1 )
BitDefenderDeepScan:Generic.Dacic.9B39DA2A.A.982A88E9
K7GWTrojan ( 005ad28d1 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.36792.2wZ@a4sKGFej
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Eyoorun.D potentially unsafe
APEXMalicious
ClamAVWin.Malware.Zusy-9819743-0
KasperskyTrojan.Win32.Agentb.bqaf
NANO-AntivirusTrojan.Win32.Agent.dufbyy
RisingTrojan.Agent!8.B1E (TFE:5:x5n5ili1I4I)
EmsisoftDeepScan:Generic.Dacic.9B39DA2A.A.982A88E9 (B)
F-SecureHeuristic.HEUR/AGEN.1316159
DrWebTrojan.MulDrop7.18312
ZillyaTrojan.Agent.Win32.3628950
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e2313819cd42b6fe
SophosMal/Generic-R
IkarusTrojan.Win32.Agentb
JiangminTrojan.Agentb.bnl
GoogleDetected
AviraHEUR/AGEN.1316159
VaristW32/Injector.A.gen!Eldorado
Antiy-AVLTrojan/Win32.Agent
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Pikabot.IP!MTB
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitDeepScan:Generic.Dacic.9B39DA2A.A.982A88E9
ZoneAlarmTrojan.Win32.Agentb.bqaf
GDataWin32.Trojan.PSE.1791Y1D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agentb.R616454
VBA32BScope.Trojan.Agentb
ALYacDeepScan:Generic.Dacic.9B39DA2A.A.982A88E9
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Agentb.wq
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.EB1!tr.dldr
AVGSf:ShellCode-C [Trj]
Cybereasonmalicious.e3531a
AvastSf:ShellCode-C [Trj]

How to remove Trojan:Win32/Pikabot.IP!MTB?

Trojan:Win32/Pikabot.IP!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment