Trojan

Trojan:Win32/Tiny.EH!MTB information

Malware Removal

The Trojan:Win32/Tiny.EH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tiny.EH!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Tiny.EH!MTB?


File Info:

name: 678FA1142BCC6C0FFDFA.mlw
path: /opt/CAPEv2/storage/binaries/2e7e80fee9fc8f44a419d1586dd52e933494de3f30f8ae7790cba7ad356b5f4f
crc32: FD535D0E
md5: 678fa1142bcc6c0ffdfa825cd5bd011b
sha1: 77f32cea64794d0c4434f2a12adbcd076fa69f77
sha256: 2e7e80fee9fc8f44a419d1586dd52e933494de3f30f8ae7790cba7ad356b5f4f
sha512: c5ffb4a6dab2fab33b557bce38d00dd6bd2e1434611a3d355a05e35615ab4c3adbf54a2e04ac0ebff0f39ebc0c19d59a922355feb3fe8df9869dde340b944304
ssdeep: 6144:zR2N0LGuHjvd1YTss408BomB6ePhrlp49MPOGyf3/09tAF:zRFrYhOPPhrlOwOa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DA4080277E89135F6F31B31AEB592614A7ABC729D35D20F23D41A0D0DB0A90EA75B73
sha3_384: 21528f5b2001af7db3130cc420ba7371b0281936d205948cc1b5d1f1fdce86c34d5d6a6962e53dc80263ba904076eed7
ep_bytes: 558bec81ec78090000e8c20c00008985
timestamp: 1970-01-01 15:50:05

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Bootstrapper for Single Installation
FileVersion: 17.9.20044.222436
InternalName: Setup.exe
LegalCopyright: Copyright © 2017 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: Setup.exe
ProductName: Bootstrapper Small
ProductVersion: 17.9.20044.222436
Translation: 0x0409 0x04e4

Trojan:Win32/Tiny.EH!MTB also known as:

LionicTrojan.Win32.Patched.trwY
DrWebWin32.HLLW.Phorpiex.1414
MicroWorld-eScanGen:Trojan.Downloader.Cu1@aOmTTOni
ALYacGen:Trojan.Downloader.Cu1@aOmTTOni
MalwarebytesMalware.AI.2715358574
ZillyaTrojan.Patched.Win32.152545
SangforDownloader.Win32.Patched.Ve4x
K7AntiVirusTrojan-Downloader ( 00552edf1 )
AlibabaTrojanDownloader:Win32/ZeroDloader.d66526c5
K7GWTrojan-Downloader ( 00552edf1 )
Cybereasonmalicious.42bcc6
BitDefenderThetaGen:NN.ZexaF.36196.Cu1@aOmTTOni
CyrenW32/ZeroDloader.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.EQH
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Patched.rw
BitDefenderGen:Trojan.Downloader.Cu1@aOmTTOni
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:DeadZero [Inf]
TencentWin32.Trojan.Patched.Vwhl
EmsisoftGen:Trojan.Downloader.Cu1@aOmTTOni (B)
F-SecureMalware.W32/Infector.Gen
VIPREGen:Trojan.Downloader.Cu1@aOmTTOni
McAfee-GW-EditionBehavesLike.Win32.Virut.gm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.678fa1142bcc6c0f
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.16VTW2Z
JiangminTrojanDownloader.Generic.beop
AviraW32/Infector.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Patched
ArcabitTrojan.Downloader.EF2F90
ZoneAlarmTrojan.Win32.Patched.rw
MicrosoftTrojan:Win32/Tiny.EH!MTB
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R282625
Acronissuspicious
McAfeeArtemis!678FA1142BCC
TACHYONWorm/W32.ZeroDownloader
VBA32BScope.TrojanBanker.CliptoShuffler
Cylanceunsafe
PandaTrj/Chgt.AC
RisingDownloader.Generic!8.141 (TFE:2:JupEv6mQ0JI)
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.EQH!tr
AVGWin32:DeadZero [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Tiny.EH!MTB?

Trojan:Win32/Tiny.EH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment