Trojan

Trojan:Win32/Tovtaker.RB!MTB removal guide

Malware Removal

The Trojan:Win32/Tovtaker.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tovtaker.RB!MTB virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Tovtaker.RB!MTB?


File Info:

name: 7425A2B438E74A9BC821.mlw
path: /opt/CAPEv2/storage/binaries/577a6f59faf43473c13cbf729894400a419e063a69a75c0d8bb51084bd50095f
crc32: 5D1AF100
md5: 7425a2b438e74a9bc821b8076285911f
sha1: d14c658b26d5ce54474d6c8c1dd63fd51a47e2e1
sha256: 577a6f59faf43473c13cbf729894400a419e063a69a75c0d8bb51084bd50095f
sha512: 3ca0a6678489a90f27c21076a71c55e950983877ded158847a0417b926d9938e9c5a9df25ba50de52ad0d14c9e31dc9e06509bc21b8e3eb14c684fc48a4634de
ssdeep: 3072:i5ZD8Rp234ZPHEf6uOeIzTe5MRkw+RIUQFv4NWOj84H:q4REIZPE1oT+U4xJH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9C36C1174C0C072E477193109F9DAA54A6DFD300F785BEBA3DC127A4F746E0AA39AA7
sha3_384: b589d2532ce2b66b0882567b141d23ec43865193e20f73915ead14fcef0f10c5d2f13fe9043b5fb1a0d729383b1bad3b
ep_bytes: e889040000e980feffff558bec6a00ff
timestamp: 2017-11-09 09:31:39

Version Info:

OriginalFilename: linja.exe
LegalCopyright: © Alabama tream. All rights reserved.
ProductVersion: 5.2.11.3
CompanyName: Gluer berrot valer
FileDescription: Klazzer gerat astream
FileVersion: 5.2.11.3
InternalName: Teebatijanerteas
ProductName: CATREPI Boes
Translation: 0x0409 0x04b0

Trojan:Win32/Tovtaker.RB!MTB also known as:

BkavW32.Common.74E91844
LionicTrojan.Win32.Tovkater.a!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fugrafa.31689
FireEyeGen:Variant.Fugrafa.31689
CAT-QuickHealPUA.MauvaiseRI.S5255025
SkyhighRDN/Generic Downloader.x
McAfeeRDN/Generic Downloader.x
Cylanceunsafe
ZillyaDownloader.Tovkater.Win32.605
SangforDownloader.Win32.Tovkater.V3dp
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Tovkater.dded5b1e
K7GWTrojan-Downloader ( 0051b8381 )
K7AntiVirusTrojan-Downloader ( 0051b8381 )
BitDefenderThetaGen:NN.ZexaF.36744.hy0@a0X06lpi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Tovkater.GX
APEXMalicious
KasperskyTrojan-Downloader.Win32.Tovkater.asgv
BitDefenderGen:Variant.Fugrafa.31689
NANO-AntivirusTrojan.Win32.InstallMonster.icpuvc
AvastWin32:Malware-gen
TencentWin32.Trojan-Downloader.Tovkater.Xwhl
EmsisoftGen:Variant.Fugrafa.31689 (B)
F-SecureTrojan.TR/Tovkater.srnuq
DrWebTrojan.InstallMonster.2414
VIPREGen:Variant.Fugrafa.31689
TrendMicroPossible_HPGen-32
Trapminemalicious.moderate.ml.score
SophosMal/Generic-R
GDataGen:Variant.Fugrafa.31689
JiangminTrojanDownloader.Tovkater.w
GoogleDetected
AviraTR/Tovkater.srnuq
VaristW32/Tovkater.Q.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Tovkater
XcitiumApplication.Win32.InstallMonster.DX@7e9j3l
ArcabitTrojan.Fugrafa.D7BC9
ViRobotTrojan.Win32.Z.Tovkater.128000
ZoneAlarmTrojan-Downloader.Win32.Tovkater.asgv
MicrosoftTrojan:Win32/Tovtaker.RB!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Abnores.R211818
VBA32TrojanDownloader.Tovkater
ALYacGen:Variant.Fugrafa.31689
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TrendMicro-HouseCallPossible_HPGen-32
RisingTrojan.Generic@AI.90 (RDML:0OQphnjGPCpo6j4s89zhwQ)
YandexTrojan.DL.Tovkater!AckeeURq5+M
IkarusTrojan-Downloader.Win32.Tovkater
MaxSecureTrojan.Malware.11559870.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.b26d5c
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Tovtaker.RB!MTB?

Trojan:Win32/Tovtaker.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment