Trojan

Should I remove “Trojan:Win32/TrickBotCrypt.FA!MTB”?

Malware Removal

The Trojan:Win32/TrickBotCrypt.FA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/TrickBotCrypt.FA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Generates some ICMP traffic
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/TrickBotCrypt.FA!MTB?


File Info:

crc32: EB32A971
md5: fddab912a958bcebcd305ef989909b24
name: FDDAB912A958BCEBCD305EF989909B24.mlw
sha1: ba420486c86fead4d16b1ccda887212d287ae895
sha256: ffaa54fe26b7cb4b86bdb7d49a5b2e609cffdc3c3db9460a77f074b503988504
sha512: 97a2942cf6d1bf605d3347d641a73838ed6335563b804a56d43bd3b202e624c3c76b55f64360677b806aa0a89cb8999abd646bfeb5062d3e44f2cd5b27e3d278
ssdeep: 12288:fgffZBLg6zjC3kbMhqQHGaDHLwC2sV/YjPCGm:fYfZNWk4vGKHAsRqC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: assent carrer
InternalName: DACOTE.dll.1, 27, 15, 17
FileVersion: 1.27.15.17
CompanyName: LEDtronics, Inc
ProductName: Thermalright Spitfire
ProductVersion: 0.0.0.0
OriginalFilename: DACOTE.dll.1, 27, 15, 17
Translation: 0x0000 0x04b0

Trojan:Win32/TrickBotCrypt.FA!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00581bd81 )
LionicTrojan.Win32.Trickpak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.16603
ALYacTrojan.GenericKDZ.77462
MalwarebytesTrojan.Banker
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/TrickBotCrypt.cc48efba
K7GWTrojan ( 00581bd81 )
ESET-NOD32a variant of Win32/Kryptik.HMHZ
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Trickpak.gen
BitDefenderTrojan.GenericKDZ.77462
MicroWorld-eScanTrojan.GenericKDZ.77462
Ad-AwareTrojan.GenericKDZ.77462
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34126.Eu0@aKKbPEjO
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.fddab912a958bceb
EmsisoftTrojan.GenericKDZ.77462 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.cpxwk
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/TrickBotCrypt.FA!MTB
GDataTrojan.GenericKDZ.77462
AhnLab-V3Trojan/Win.Trickbot.R440003
McAfeeTrickbot-FTWI!FDDAB912A958
MAXmalware (ai score=82)
VBA32BScope.TrojanBanker.Trickster
PandaTrj/CI.A
YandexTrojan.Trickpak!iDRDl11zMwI
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMHZ!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/TrickBotCrypt.FA!MTB?

Trojan:Win32/TrickBotCrypt.FA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment