Worm

How to remove “Worm:Win32/Mytob.RR”?

Malware Removal

The Worm:Win32/Mytob.RR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Mytob.RR virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Worm:Win32/Mytob.RR?


File Info:

crc32: A4EC5066
md5: ec78c5982c7d1a3c191faff85dbccddb
name: EC78C5982C7D1A3C191FAFF85DBCCDDB.mlw
sha1: 254999c1956f2eef2fd56728337776dede6218c9
sha256: 8bdb821f787336cc592ff40a1beccfae6997beb7e7f3277e450c1768636d2641
sha512: d061a6be23aff6247be1069d3e6eb4fa989ae47ce7ad47aaa1e7e773ce697e8f2e8b5f7fbfb41f1daa2fad628bd2ca95e3edd3ca58b9717462a66482e6f2205d
ssdeep: 1536:GAG4lXVB1WRydFMQaTRMfTphQquZ7bz0WpwA2cIIVDGQY+pIhrL6pnv:GAJthQqQbzzVRI25Y2+v2v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Mytob.RR also known as:

BkavW32.Gatekeeper.Trojan
K7AntiVirusTrojan ( 000015c21 )
LionicWorm.Win32.Fearso.lDrx
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.13408
CynetMalicious (score: 100)
CAT-QuickHealWorm.Agent
ALYacWin32.Worm.Mytob.DBF
CylanceUnsafe
ZillyaBackdoor.CPEX.Win32.25500
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:Win32/DelfInject.de6d7448
K7GWTrojan ( 000015c21 )
Cybereasonmalicious.82c7d1
TrendMicroWORM_NUWAR.AXQ
BaiduWin32.Worm.AutoRun.ed
CyrenW32/Trojan.BSPJ-6834
SymantecW32.Mytob@mm
ESET-NOD32Win32/AutoRun.TT
ZonerTrojan.Win32.945
APEXMalicious
TotalDefenseWin32/Rbot.JEO
AvastWin32:Delf-KXC [Drp]
ClamAVWin.Worm.W-406
KasperskyP2P-Worm.Win32.Agent.ez
BitDefenderWin32.Worm.Mytob.DBF
NANO-AntivirusTrojan.Win32.Delf.fyxt
ViRobotDropper.Delf.26624.B
MicroWorld-eScanWin32.Worm.Mytob.DBF
TencentWin32.Trojan.Inject.Auto
Ad-AwareWin32.Worm.Mytob.DBF
SophosMal/Basine-C
ComodoTrojWare.Win32.TrojanSpy.Inject.~A@12zqm
F-SecureWorm.WORM/Mytob.99328
BitDefenderThetaAI:Packer.76DE0FA21F
VIPRETrojan.Win32.Generic!BT
InvinceaML/PE-A + Mal/Basine-C
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
FireEyeGeneric.mg.ec78c5982c7d1a3c
EmsisoftWin32.Worm.Mytob.DBF (B)
SentinelOneDFI – Malicious PE
JiangminTrojanDropper.Delf.aog
WebrootW32.Trojan.Worm.Gen.X
AviraWORM/Mytob.99328
eGambitUnsafe.AI_Score_92%
Antiy-AVLWorm[P2P]/Win32.Agent
MicrosoftWorm:Win32/Mytob.RR
ArcabitWin32.Worm.Mytob.DBF
SUPERAntiSpywareTrojan.Duncan/ActiveSpy
ZoneAlarmP2P-Worm.Win32.Agent.ez
GDataWin32.Worm.Mytob.DBF
AhnLab-V3Trojan/Win32.Agent.C56948
Acronissuspicious
McAfeeW32/Mydoom.y.gen@MM
MAXmalware (ai score=100)
VBA32Trojan-Dropper.Win32.Fufel
PandaW32/P2Pworm.E.worm
TrendMicro-HouseCallWORM_NUWAR.AXQ
RisingBackdoor.Win32.IRCbot.apj (CLASSIC)
YandexTrojan.Delfinject.Gen.3
IkarusTrojan.Win32.Buzus
FortinetW32/Injector.fam!tr
AVGWin32:Delf-KXC [Drp]
Paloaltogeneric.ml
Qihoo-360Malware.Radar01.Gen

How to remove Worm:Win32/Mytob.RR?

Worm:Win32/Mytob.RR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment