Trojan

Trojan:Win32/Sfone.RE!MTB removal

Malware Removal

The Trojan:Win32/Sfone.RE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sfone.RE!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Sfone.RE!MTB?


File Info:

name: EA3FF20CBD03F9A6ECD0.mlw
path: /opt/CAPEv2/storage/binaries/31616790480784e5e670dab1ddc2f2f8cd7e9520469ecf9945f04f5882a1829b
crc32: 54ED38F0
md5: ea3ff20cbd03f9a6ecd058a15494ce5c
sha1: eab036acf34d3788c6387e9ac6cb30fa213d0a7d
sha256: 31616790480784e5e670dab1ddc2f2f8cd7e9520469ecf9945f04f5882a1829b
sha512: 5dc107c1515d713f78882170746fcd213ecdceb8bd1bb9f9d17b2e6e45948cee6b9d22f116b4090a24110d7029c2a7f16155e5fcde23f1ce1cefe26ed7b2457c
ssdeep: 768:QYyI06qR96ah5nWLQF/NwwCiS5B8c9sZxRXDgZ:QnN3R96K5WLiVwtXf9sa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A133D5D2A893917D0CA09385E41D9161171A74810EA8F43FEA297BFEEDF6A43504FB3
sha3_384: 5dfd89356981c27f851b63fef3c32606a63d8a291f6b97c23a7d519e953ea27cb61f58045b895ad13dc0d14c3ef3f230
ep_bytes: 60be150041008dbeeb0fffff5783cdff
timestamp: 2006-03-02 17:50:37

Version Info:

0: [No Data]

Trojan:Win32/Sfone.RE!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.GDZN
ClamAVWin.Malware.Eclz-9953021-0
FireEyeGeneric.mg.ea3ff20cbd03f9a6
Cylanceunsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.cbd03f
BitDefenderThetaAI:Packer.06CA605E1B
CyrenW32/Backdoor.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
AvastWin32:Agent-URR [Trj]
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.GenericML.xnet
BitDefenderTrojan.Agent.GDZN
SophosML/PE-A
F-SecureTrojan.TR/Crypt.ULPM.Gen
ZillyaTrojan.Sdum.Win32.8821
McAfee-GW-EditionBehavesLike.Win32.Generic.pm
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.GDZN (B)
GDataTrojan.Agent.GDZN
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.ULPM
ArcabitTrojan.Agent.GDZN
ZoneAlarmVHO:Trojan.Win32.GenericML.xnet
MicrosoftTrojan:Win32/Sfone.RE!MTB
GoogleDetected
AhnLab-V3Malware/Win.Generic.R510320
Acronissuspicious
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
APEXMalicious
RisingTrojan.Sdum!8.1155F (C64:YzY0Oof7VWl3LJkk)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.185628869.susgen
FortinetW32/ULPM.2C75!tr
AVGWin32:Agent-URR [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Sfone.RE!MTB?

Trojan:Win32/Sfone.RE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment