Trojan

Trojan:Win32/PonyStealer.PE!MTB removal instruction

Malware Removal

The Trojan:Win32/PonyStealer.PE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/PonyStealer.PE!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/PonyStealer.PE!MTB?


File Info:

crc32: 6BC606CA
md5: 7e61b2b7856c264f9f70ccaef847494c
name: az1.exe
sha1: aa0c219b24a943d0276cb98c3bd6237f24dd6887
sha256: 2530a6515fbfa1c1828dfe9cf174709002d10b9ae832176fc98fe5679a23bf13
sha512: 60b26c9acb0379fa8cb272eeac46d5a08766e5a00389121091ec66d255a5b2d1e4903346e963e097df6b88378e201b44f31d1bfc2117d3d9efc40e90284d5508
ssdeep: 768:gsDEzi7ByEmosJCCTZ91ARPrssBnzcXs6YyOcVv71fPDR5gKPyw1hD:vDErFxJARPrNBzJs1zl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Overblik6
FileVersion: 2.06
CompanyName: Noodles
ProductName: skinde
ProductVersion: 2.06
OriginalFilename: Overblik6.exe

Trojan:Win32/PonyStealer.PE!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.33830995
McAfeeFareit-FTA!7E61B2B7856C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005669fc1 )
BitDefenderTrojan.GenericKD.33830995
K7GWTrojan ( 005669fc1 )
F-ProtW32/VBKrypt.AKP.gen!Eldorado
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-7788440-0
GDataTrojan.GenericKD.33830995
KasperskyTrojan-PSW.Win32.Azorult.anlz
AlibabaTrojanPSW:Win32/Azorult.2d7d2349
AegisLabTrojan.Win32.Azorult.i!c
TencentWin32.Trojan-qqpass.Qqrob.Akfh
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33830995 (B)
F-SecureTrojan.TR/Injector.hmxvo
TrendMicroTROJ_GEN.R02DC0WEE20
McAfee-GW-EditionBehavesLike.Win32.Fareit.mz
Trapminesuspicious.low.ml.score
SophosMal/FareitVB-AB
IkarusTrojan.VB.Crypt
CyrenW32/VBKrypt.AKP.gen!Eldorado
AviraTR/Injector.hmxvo
WebrootW32.Trojan.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Azorult
ArcabitTrojan.Generic.D2043853
ZoneAlarmTrojan-PSW.Win32.Azorult.anlz
MicrosoftTrojan:Win32/PonyStealer.PE!MTB
AhnLab-V3Trojan/Win32.Injector.R336292
ALYacTrojan.GenericKD.33830995
Ad-AwareTrojan.GenericKD.33830995
MalwarebytesTrojan.GuLoader
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELXQ
TrendMicro-HouseCallTROJ_GEN.R02DC0WEE20
RisingTrojan.Injector!1.C624 (CLOUD)
eGambitUnsafe.AI_Score_95%
FortinetW32/Injector.ELXM!tr
BitDefenderThetaGen:NN.ZevbaCO.34110.fm0@aq!Mr3gi
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.PSW.032

How to remove Trojan:Win32/PonyStealer.PE!MTB?

Trojan:Win32/PonyStealer.PE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment