Trojan

Trojan:Win32/Trickbot.EF!MTB removal guide

Malware Removal

The Trojan:Win32/Trickbot.EF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Trickbot.EF!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Trojan:Win32/Trickbot.EF!MTB?


File Info:

name: A51AAF75EF50BE944EDF.mlw
path: /opt/CAPEv2/storage/binaries/4a5a352132479a80fed33ebec9da0faf424329dacc20e37338e3a22effe8705b
crc32: CB45891F
md5: a51aaf75ef50be944edf02065bbb251b
sha1: ed46c1b939dae0036988627402183412d8c05824
sha256: 4a5a352132479a80fed33ebec9da0faf424329dacc20e37338e3a22effe8705b
sha512: 746a4fdab688ddc0d1aeb740ea81951a7a8c05b31b60cda21dd110415d94671e6195485c1705aea9d53f190142ff84d78c856b464a9a9fb718f501a84fedbf52
ssdeep: 12288:0BnAIpZb9hNC5K25bw1YIRLd/fSMg47xBmk0gVZRf0I:+pZb9hB25Od/KJ4zmkRZRsI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EF4BE02B2D1C137F6E202724FE7AFF7DAF5B9114A296447F3E62B0C1971A434936A61
sha3_384: 281c142dee35fb18990ae8d8c9a8751267289cdd1d8d0d28ea711b0406f5eb1b7c43312e6a4dac2b725ceab9be6f3908
ep_bytes: 558bec6aff68e8fb440068e43f410064
timestamp: 2021-04-08 10:06:13

Version Info:

CompanyName:
FileDescription: zlicker_free MFC Application
FileVersion: 1, 0, 0, 1
InternalName: zlicker_free
LegalCopyright: Copyright (C) 2002
LegalTrademarks:
OriginalFilename: zlicker_free.EXE
ProductName: zlicker_free Application
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Trojan:Win32/Trickbot.EF!MTB also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.75025
ClamAVWin.Malware.Generickdz-9860049-0
FireEyeGeneric.mg.a51aaf75ef50be94
CAT-QuickHealTrojan.TrickpakPMF.S20498057
McAfeeTrickbot-FTPR!A51AAF75EF50
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.84153
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0057c3ab1 )
AlibabaTrojan:Win32/Trickbot.fac8263c
K7GWTrojan ( 0057c3ab1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.EBG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FFBA
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Trickpak.gen
BitDefenderTrojan.GenericKDZ.75025
NANO-AntivirusTrojan.Win32.Trickpak.ivjlxt
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.10ce5d46
Ad-AwareTrojan.GenericKDZ.75025
EmsisoftTrojan.GenericKDZ.75025 (B)
DrWebTrojan.KillProc2.15961
VIPRETrojan.GenericKDZ.75025
McAfee-GW-EditionTrickbot-FTPR!A51AAF75EF50
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Trickb-M
IkarusTrojan.Win32.Krypt
GDataTrojan.GenericKDZ.75025
JiangminTrojan.Trickpak.eb
AviraHEUR/AGEN.1228285
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.5123
MicrosoftTrojan:Win32/Trickbot.EF!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Agent.R420735
Acronissuspicious
ALYacTrojan.GenericKDZ.75025
TACHYONTrojan/W32.Trickpak.757828
VBA32BScope.Trojan-Dropper.Injector
MalwarebytesMalware.AI.1987072524
RisingTrojan.Kryptik!1.D78B (CLASSIC)
YandexTrojan.Trickpak!NI5PuXqkb6k
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.109946090.susgen
FortinetW32/GenKryptik.FFBA!tr
AVGWin32:BankerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Trojan:Win32/Trickbot.EF!MTB?

Trojan:Win32/Trickbot.EF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment