Malware

VirTool:Win32/AccessMe.A!MTB (file analysis)

Malware Removal

The VirTool:Win32/AccessMe.A!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/AccessMe.A!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine VirTool:Win32/AccessMe.A!MTB?


File Info:

crc32: 800C9228
md5: c75c0e66020e0fe954f02cacd2383821
name: C75C0E66020E0FE954F02CACD2383821.mlw
sha1: 65efc9aff59311198093b5a4e7a827b61bdb3b44
sha256: f463dd66e4a9fc1270d824f4d5305e9e5e5a7831bdf7ad15c45bbfef9c0460bb
sha512: 571e7afc41a5fea83af307c88c81abb11977a24edc648d785c46b01ef7e2125f7fda628674fc99199189d47dc90fb91a30cc0d47aca4c21f5c0b3ee7b72d35ce
ssdeep: 768:AR9l2DerbSNNUrfbdx4jbTTM+mTOAQNfy0gnQz6+yLm8o7P3ymTh4aVb90efa1/S:dWbSNEbDSPw+ST+yqtOajOBNvu4l6DF
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/AccessMe.A!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader38.14964
ClamAVWin.Exploit.Deepscan-9886499-0
ALYacDeepScan:Generic.Exploit.Shellcode.3.C366E2C5
CylanceUnsafe
ZillyaTrojan.Rozena.Win32.113518
SangforTrojan.Win32.Save.a
K7GWTrojan ( 005754491 )
K7AntiVirusTrojan ( 005754491 )
CyrenW32/Agent.CWV.gen!Eldorado
ESET-NOD32a variant of Win32/Rozena.AZG
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Exploit.Shellcode.3.C366E2C5
MicroWorld-eScanDeepScan:Generic.Exploit.Shellcode.3.C366E2C5
Ad-AwareDeepScan:Generic.Exploit.Shellcode.3.C366E2C5
BitDefenderThetaGen:NN.ZexaF.34170.g8Y@aaEI6Be
McAfee-GW-EditionGenericRXNC-FJ!C75C0E66020E
FireEyeGeneric.mg.c75c0e66020e0fe9
EmsisoftDeepScan:Generic.Exploit.Shellcode.3.C366E2C5 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftVirTool:Win32/AccessMe.A!MTB
GDataDeepScan:Generic.Exploit.Shellcode.3.C366E2C5
AhnLab-V3Malware/Win32.RL_Generic.R359851
McAfeeGenericRXNC-FJ!C75C0E66020E
MAXmalware (ai score=87)
VBA32BScope.Trojan.Swrort
MalwarebytesMalware.AI.846375514
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R005C0DIN21
IkarusTrojan.Win32.Meterpreter
FortinetW32/Rozena.AZG!tr
AVGWin32:Trojan-gen

How to remove VirTool:Win32/AccessMe.A!MTB?

VirTool:Win32/AccessMe.A!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment