Malware

VirTool:MSIL/Denigrate.A!MTB removal

Malware Removal

The VirTool:MSIL/Denigrate.A!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:MSIL/Denigrate.A!MTB virus can do?

  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine VirTool:MSIL/Denigrate.A!MTB?


File Info:

name: A1F663A7778309E3FE3F.mlw
path: /opt/CAPEv2/storage/binaries/bbe1a370716bcf5954de7c4f565e7ad7d2c85ae235e8bca083c7af1b523ea40f
crc32: 60861579
md5: a1f663a7778309e3fe3f4fb07ce8abac
sha1: 459bbf85eae051711d2c0a4056c3670df5c33937
sha256: bbe1a370716bcf5954de7c4f565e7ad7d2c85ae235e8bca083c7af1b523ea40f
sha512: 5456bff354c1e5ef588f29ebab3bb9532faf23b5247ba781714225120e9cd5d1be09b7f01295e849b7319e9e7f23d8e967f6c40d359fb0ac8352db3b20ee6bd7
ssdeep: 3072:8Ubo9OwHUBE97pdWZYlRO4yPN9cSJIBHW6MEY7Sq3bfEMTcK9dYpjwavuDLIGt4:w9OIzdWZqOHPRyBH5MEY7Sq3bfEDKf+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D974F70433A1913CFDDE5FB1A4300D6E5FB9DD462319F7AA9860E8F72E42F40A50666E
sha3_384: 34c75eb37c1032bee3a2760d1a706fda825d73825537cf2e430d39d25aa0a924646a7b8b8c2c4e04ccd09b311cfd8557
ep_bytes: ff25002040004e45474f455854530100
timestamp: 2050-12-31 02:46:23

Version Info:

Translation: 0x0000 0x04b0
CompanyName: oblivion
FileDescription: oblivion
FileVersion: 2.0.0.0
InternalName: oblivion.exe
LegalCopyright:
OriginalFilename: oblivion.exe
ProductName: oblivion
ProductVersion: 2.0.0
Assembly Version: 2.0.0.0

VirTool:MSIL/Denigrate.A!MTB also known as:

BkavW32.Common.42B58F20
LionicTrojan.Win32.Denigrate.4!c
MicroWorld-eScanGen:Variant.Cerbu.115812
FireEyeGen:Variant.Cerbu.115812
SkyhighBehavesLike.Win32.ALogger.fh
McAfeeArtemis!A1F663A77783
Cylanceunsafe
ZillyaTool.Inveigh.Win32.35
SangforHacktool.Msil.Denigrate.Vlfn
AlibabaVirTool:MSIL/Denigrate.ffddc4ef
Cybereasonmalicious.777830
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
TrendMicro-HouseCallTROJ_GEN.R002C0DA924
KasperskyHEUR:Trojan.MSIL.Crypt.c
BitDefenderGen:Variant.Cerbu.115812
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13fc78d6
EmsisoftGen:Variant.Cerbu.115812 (B)
F-SecureHeuristic.HEUR/AGEN.1305691
VIPREGen:Variant.Cerbu.115812
TrendMicroTROJ_GEN.R002C0DA924
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
GoogleDetected
AviraHEUR/AGEN.1305691
VaristW32/ABRisk.YIYG-4966
MicrosoftVirTool:MSIL/Denigrate.A!MTB
ArcabitTrojan.Cerbu.D1C464
ZoneAlarmHEUR:Trojan.MSIL.Crypt.c
GDataGen:Variant.Cerbu.115812
AhnLab-V3Malware/Win.Denigrate.C4627527
ALYacGen:Variant.Cerbu.115812
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3925089602
PandaTrj/GdSda.A
RisingTrojan.Crypt!8.2E3 (CLOUD)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.124215711.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove VirTool:MSIL/Denigrate.A!MTB?

VirTool:MSIL/Denigrate.A!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment