Worm

Win32.Worm.Mytob.DBN removal guide

Malware Removal

The Win32.Worm.Mytob.DBN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.Mytob.DBN virus can do?

  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • The sample wrote data to the system hosts file.
  • Binary compilation timestomping detected

How to determine Win32.Worm.Mytob.DBN?


File Info:

name: B564B82A1048125E9B78.mlw
path: /opt/CAPEv2/storage/binaries/49de49f955c4cda94cea1a099d4fe059dc5e3ba063a3495ed82692d82982b12a
crc32: A0923B39
md5: b564b82a1048125e9b78f1ab4dc3639e
sha1: a0548828450d3233b7b1c5c40cf416e5c376a17d
sha256: 49de49f955c4cda94cea1a099d4fe059dc5e3ba063a3495ed82692d82982b12a
sha512: 54d4ff0d8863e26a6df78ddf6808db309343c64355725033da57a3761e7e45e7314d9b9917056ee525710bba6adbde1aee782145873208d4a255196ea6fe6ad1
ssdeep: 3072:7ZridCG2GX7+V1knt5e3Xyz8l+DQMiZv:7kdB2GiV1kLJHQFZv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3C34BADB00D4411C9F22DB088288425652BCFB696383AC3177EF7BD55AA873465F39F
sha3_384: c47ad65945928233b66e058ea0fc512099b10d888b8fb53b52c4f73bca2ee4473a561c5e58b1129b2294c45a83544bcf
ep_bytes: e9550000005a565750515389d3e84801
timestamp: 2106-02-07 06:28:15

Version Info:

0: [No Data]

Win32.Worm.Mytob.DBN also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Worm.Mytob.DBN
FireEyeGeneric.mg.b564b82a1048125e
CAT-QuickHealBackdoor.Agobot.13478
ALYacWin32.Worm.Mytob.DBN
CylanceUnsafe
ZillyaWorm.Mytob.Win32.145
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderWin32.Worm.Mytob.DBN
K7GWTrojan ( 00553f0b1 )
K7AntiVirusTrojan ( 00553f0b1 )
BitDefenderThetaAI:FileInfector.86F2A80714
VirITI-WORM.Mytob.BX
CyrenW32/Mytob.GW@mm
SymantecW32.Gaobot.gen!poly
ESET-NOD32Win32/Mytob.FY
TrendMicro-HouseCallMal_Bot
ClamAVWin.Worm.Mytob-406
KasperskyNet-Worm.Win32.Mytob.bi
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotWorm.Win32.Agobot.gen
RisingWorm.Mytob.fr (RDMK:cmRtazpVKss4at/1Gb2ZFPLUeWvk)
ComodoBackdoor.Win32.Agobot.hn0@1d9dgj
DrWebWin32.HLLW.Agobot
VIPREWorm.Win32.Mytob.dn (v)
TrendMicroMal_Bot
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cm
SentinelOneStatic AI – Malicious PE
EmsisoftWin32.Worm.Mytob.DBN (B)
APEXMalicious
JiangminI-Worm/Mytob.bj
eGambitUnsafe.AI_Score_99%
AviraWORM/Mytob.HE
Antiy-AVLTrojan/Generic.ASBOL.C5D2
MicrosoftWorm:Win32/Gaobot
GDataWin32.Worm.Mytob.DBN
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.IRCBot.R7768
McAfeeW32/Polybot@MM
MAXmalware (ai score=86)
VBA32Win32.Trojan.Hoster.Heur
MalwarebytesWorm.Mytob
PandaW32/Mytob.MI.worm
TencentMalware.Win32.Gencirc.10b54d81
YandexTrojan.GenAsa!15KKm9zmWMQ
TACHYONWorm/W32.Mytob.Gen
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AgoBot.fam!worm
AVGWin32:HBPECrypt-A [Wrm]
Cybereasonmalicious.a10481
AvastWin32:HBPECrypt-A [Wrm]

How to remove Win32.Worm.Mytob.DBN?

Win32.Worm.Mytob.DBN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment