Trojan

Should I remove “Trojan:Win32/Reconyc!MTB”?

Malware Removal

The Trojan:Win32/Reconyc!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Reconyc!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Reconyc!MTB?


File Info:

crc32: A6ED4F3B
md5: eff14a9d26f605d4489cc7cd0eb37e02
name: EFF14A9D26F605D4489CC7CD0EB37E02.mlw
sha1: 19e8dfcb3b0d56a6c60137ac497d8df4e7459f5c
sha256: f9fb564504a1718ba3c5b745ea03bedaa55bc9dfe30dbbf3744979b789d97645
sha512: decde79642a0d51583a9854b344af9b9dc9f38c75ffa7fb6e2d1c6f3f97e28279cd3339805985f44994d7013787d073c09f56ed70e4e1843886915ab08f54386
ssdeep: 12288:WRZ+IoG/n9IQxW3OBseW5HFb7tfXUQh76Uhr:Q2G/nvxW3Wwlh7tfX/vd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Reconyc!MTB also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebBAT.DownLoader.628
CAT-QuickHealTrojan.PE_EXE
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Reconyc.606dbfbe
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b3b0d5
CyrenVBS/Agent.ADO
SymantecTrojan.Gen.MBT
ESET-NOD32BAT/TrojanDownloader.Agent.OHJ
ZonerTrojan.Win32.118318
APEXMalicious
AvastOther:Malware-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Reconyc.ogjw
BitDefenderTrojan.GenericKD.46564393
NANO-AntivirusTrojan.Win32.Reconyc.ixextv
ViRobotTrojan.Win32.Z.Agent.518855
MicroWorld-eScanTrojan.GenericKD.46564393
TencentWin32.Trojan.Reconyc.Aqqb
Ad-AwareTrojan.GenericKD.46564393
SophosMal/Generic-R + Troj/Azorult-IJ
ComodoMalware@#219b8keglbk56
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.NEGASTEAL.DOCJZ
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
FireEyeGeneric.mg.eff14a9d26f605d4
EmsisoftTrojan.GenericKD.46564393 (B)
AviraTR/Dldr.Reconyc.A
MicrosoftTrojan:Win32/Reconyc!MTB
ArcabitTrojan.Generic.D2C68429
GDataWin32.Trojan.Agent.EK9QQS
AhnLab-V3Malware/Win.Generic.C4535343
VBA32Trojan.Reconyc
MAXmalware (ai score=84)
MalwarebytesMalware.AI.1117462035
PandaTrj/WLT.G
TrendMicro-HouseCallTrojan.Win32.NEGASTEAL.DOCJZ
YandexTrojan.Etecer.bWdaRg.46
IkarusTrojan.Inject
MaxSecureTrojan.Malware.120216944.susgen
FortinetW32/Agent.7E02!tr
AVGOther:Malware-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Reconyc!MTB?

Trojan:Win32/Reconyc!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment