Ransom

MBR:Ransom-A [Rtk] information

Malware Removal

The MBR:Ransom-A [Rtk] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MBR:Ransom-A [Rtk] virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Likely installs a bootkit via raw harddisk modifications
  • Deletes its original binary from disk
  • Attempts to restart the guest VM
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine MBR:Ransom-A [Rtk]?


File Info:

crc32: 638CC21A
md5: e34ff25373c3cb3d24aea70273942b73
name: E34FF25373C3CB3D24AEA70273942B73.mlw
sha1: 39a615d30f483f72b3de63ba904759ffe9cfee1a
sha256: d6ca937b595f49b770fee6b7a8a304d2d82cc861411e008bb75be8cff87363d7
sha512: 3dac25cab279965300f9d84700e53c979a5478a15e298374f1fb04731ec32e8d6b70e3178422d08434c4353ec60f83847703ed3dfd6065e361f4d0803395f6a1
ssdeep: 96:ylbrqC4RquUqCLm8VlTckBcf0hKMqizvWkQtgw:orqvqucLm8VrcchKMqijQtgw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MBR:Ransom-A [Rtk] also known as:

K7AntiVirusTrojan ( 0029be2d1 )
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.6
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeRansom-FIT!E34FF25373C3
CylanceUnsafe
ZillyaTrojan.Mbro.Win32.58
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Genasom.bf84af8f
K7GWTrojan ( 0029be2d1 )
Cybereasonmalicious.373c3c
CyrenW32/Ransom.X.gen!Eldorado
ESET-NOD32a variant of Win32/MBRlock.R
APEXMalicious
TotalDefenseWin32/Ransom.AFV
AvastMBR:Ransom-A [Rtk]
ClamAVWin.Trojan.Ransom-43
KasperskyTrojan-Ransom.Win32.Mbro.rv
BitDefenderGen:Variant.Zusy.327945
NANO-AntivirusTrojan.Win32.Mbro.fqiitq
ViRobotTrojan.Win32.A.Mbro.139264
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
MicroWorld-eScanGen:Variant.Zusy.327945
TencentWin32.Trojan.Mbro.Ahyd
Ad-AwareGen:Variant.Zusy.327945
SophosMal/Generic-S
ComodoTrojWare.Win32.Trojan.Agent.~CRP@3xxg3u
BitDefenderThetaAI:Packer.1BE16E5D1D
VIPRETrojan.Win32.Ransom.dva (v)
TrendMicroTROJ_RANSOM_BL13015C.TOMC
McAfee-GW-EditionBehavesLike.Win32.Detnat.lt
FireEyeGeneric.mg.e34ff25373c3cb3d
EmsisoftGen:Variant.Zusy.327945 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.ifva
WebrootW32.Trojan.Gen
AviraBOO/Ransom.AB
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Genasom.DV
ArcabitTrojan.Zusy.D50109
AegisLabTrojan.Win32.Mbro.luc6
ZoneAlarmTrojan-Ransom.Win32.Mbro.rv
GDataGen:Variant.Zusy.327945
TACHYONTrojan/W32.Small.10240.IS
AhnLab-V3Trojan/Win32.Mbro.C67070
Acronissuspicious
VBA32Trojan.Ransom.5705
MAXmalware (ai score=100)
MalwarebytesRansom.FileCryptor
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RANSOM_BL13015C.TOMC
RisingTrojan.MBRlock!1.66BD (CLOUD)
YandexTrojan.GenAsa!lGGJPPymHD4
IkarusTrojan-Ransom.Mbro
MaxSecureTrojan.Malware.2517593.susgen
FortinetW32/MBRlock.C!tr
AVGMBR:Ransom-A [Rtk]
Qihoo-360Win32/Ransom.Genasom.HxMBEpsA

How to remove MBR:Ransom-A [Rtk]?

MBR:Ransom-A [Rtk] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment