Trojan

What is “Trojan:Win32/Uztuby.KAA!MTB”?

Malware Removal

The Trojan:Win32/Uztuby.KAA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Uztuby.KAA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Uztuby.KAA!MTB?


File Info:

name: 0C7524AA4B680015E879.mlw
path: /opt/CAPEv2/storage/binaries/d46a545747836c92c0b8a9b03e2004f0652b215b310022eb5fb8d575f98b7e3a
crc32: A929D62C
md5: 0c7524aa4b680015e87970e54b7615b3
sha1: e1c1abe669f721bef99d66354625b57dbe484354
sha256: d46a545747836c92c0b8a9b03e2004f0652b215b310022eb5fb8d575f98b7e3a
sha512: 0decfe37c2a06942bb68898fcd4e446ec3041f1aa6f2d2c7e412429b760bed8da8205c7191c1a9d249c7a3ec9361c36852673a8c4a417a5eaa3480ccab0fa9b2
ssdeep: 49152:V1dS/66powrdaia+RrKzAA+kc+C//buW4:V1KJ5a+d0cd7uW4
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T14CB5D0B2B99DE96FD14E657E017513B042AA0E9445D30C35BF7ACAD0CB273E04C686AF
sha3_384: 1540782b973cc17ed6b2d14f72de88473a3feb3576e3ecff080b075d7a10a73f3a219805fb7407d8e343d6d41069475f
ep_bytes: 89e0508f053474211029c2e811000000
timestamp: 2004-10-22 14:34:27

Version Info:

Comments: Provided under the terms of the GNU Lesser General Public License.
CompanyName: g10 Code GmbH
FileDescription: GPGME - GnuPG Made Easy
FileVersion: 33.22.0.f9c923bb
InternalName: gpgme
LegalCopyright: Copyright © 2001-2018 g10 Code GmbH
LegalTrademarks:
OriginalFilename: gpgme.dll
PrivateBuild:
ProductName: GPGME
ProductVersion: 1.13.1-beta21
SpecialBuild:

Trojan:Win32/Uztuby.KAA!MTB also known as:

BkavW32.Common.382229FE
LionicTrojan.Win32.Fero.a!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGen:Variant.Mikey.162574
CAT-QuickHealTrojandownloader.Fero
SkyhighBehavesLike.Win32.Downloader.vc
McAfeeGenericRXWN-JH!0C7524AA4B68
Cylanceunsafe
VIPREGen:Variant.Mikey.162574
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005b0b6e1 )
K7AntiVirusTrojan ( 005b0b6e1 )
SymantecTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HVZK
APEXMalicious
ClamAVWin.Packed.Fero-10019561-0
KasperskyTrojan-Downloader.Win32.Fero.hls
AlibabaTrojanDownloader:Win32/Uztuby.22465b11
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win.Z.Mikey.2310144.A
MicroWorld-eScanGen:Variant.Mikey.162574
AvastWin32:Roshtyak-H [Trj]
TencentMalware.Win32.Gencirc.14040be9
TrendMicroTROJ_GEN.R002C0DB124
Trapminemalicious.high.ml.score
SophosMal/Generic-S
GoogleDetected
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.a
ArcabitTrojan.Mikey.D27B0E
ZoneAlarmTrojan-Downloader.Win32.Fero.hls
MicrosoftTrojan:Win32/Uztuby.KAA!MTB
VaristW32/Kryptik.LCO.gen!Eldorado
AhnLab-V3Dropper/Win.Generic.R631658
ALYacGen:Variant.Mikey.162574
MAXmalware (ai score=86)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DB124
RisingDownloader.Fero!8.18DAE (TFE:2:eeAvFuvJ41D)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.220586565.susgen
FortinetW32/Kryptik.HVWI!tr
AVGWin32:Roshtyak-H [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Uztuby.KAA!MTB?

Trojan:Win32/Uztuby.KAA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment