Trojan

Trojan:Win32/WinLNK.DR!MTB removal

Malware Removal

The Trojan:Win32/WinLNK.DR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WinLNK.DR!MTB virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/WinLNK.DR!MTB?


File Info:

crc32: 6F77C41B
md5: 41f00b462da680d6d8fc82116681471c
name: upload_file
sha1: 6012c20b523414e43e4e7518b0ac1a5b251ca6bc
sha256: 8fc83009aab5f179e8267061f7796b848c1da64d51021492f47c236498eee7fd
sha512: df032ccdeaa24d29cba03cbced39ab57742fa7b7b12ceee141576d5473ab6e4bf1a112765db900ffd0ef0c45485eeb18914b4f443508bee00868c1e1c2966456
ssdeep: 24:84ZppQaS38An1RcKsy8cS6cehBh8cs/qCf:8wnG1+E8N/qCf
type: MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Working directory, Has command line arguments, Icon, Archive, ctime=Mon Feb 24 00:00:35 2020, mtime=Mon Feb 24 00:00:35 2020, atime=Mon Feb 24 00:00:35 2020, length=13824, window=hide

Version Info:

0: [No Data]

Trojan:Win32/WinLNK.DR!MTB also known as:

FireEyeHeur.BZC.YAX.Nioc.1.053F987C
AegisLabTrojan.WinLNK.Nioc.4!c
ArcabitHeur.BZC.YAX.Nioc.1.07376BBB
CyrenLNK/Trojan.PIPC-1
SymantecTrojan.Malscript
TrendMicro-HouseCallTROJ_FRS.VSNTG120
AvastOther:Malware-gen [Trj]
KasperskyHEUR:Trojan.WinLNK.Agent.gen
BitDefenderHeur.BZC.YAX.Nioc.1.053F987C
MicroWorld-eScanHeur.BZC.YAX.Nioc.1.053F987C
Ad-AwareHeur.BZC.YAX.Nioc.1.053F987C
EmsisoftHeur.BZC.YAX.Nioc.1.053F987C (B)
TrendMicroTROJ_FRS.VSNTG120
SophosTroj/DownLnk-X
F-ProtLNK/Trojan.PIPC-1
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/WinLNK.DR!MTB
ZoneAlarmHEUR:Trojan.WinLNK.Agent.gen
ALYacTrojan.Downloader.LnK.Gen
ZonerProbably Heur.LNKScript
IkarusTrojan.Agent
GDataHeur.BZC.YAX.Nioc.1.07376BBB
AVGOther:Malware-gen [Trj]
Qihoo-360susp.lnk.script

How to remove Trojan:Win32/WinLNK.DR!MTB?

Trojan:Win32/WinLNK.DR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment