Malware

About “Malware-Cryptor.MTA” infection

Malware Removal

The Malware-Cryptor.MTA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware-Cryptor.MTA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics
  • Attempts to modify user notification settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware-Cryptor.MTA?


File Info:

crc32: 8449CE03
md5: 3b5003731ea8603caff163785ce244ba
name: 3B5003731EA8603CAFF163785CE244BA.mlw
sha1: 014ae1ed4529e42c96d9fd8b20436f09f03a6069
sha256: 327a52760d693b17c8b6aecb37e860baa486ed36d918ffd3462df9e21f8ea290
sha512: 19efb5227c6e367f5ba44048ba1d5b20485d38a910e656eddd8bad56163fd3e99698434da09fdff9fc12062fc6408b202a6b2da757759e5e7dbd6bc31b00830c
ssdeep: 12288:c2UgaPCfZKhdhE8QCuEuKmvIghfUy+SmuVyoatihLzm:c2UJQ2rgZKmm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: All Rights reserved xa9 2005-2009
FileDescription: AVASetup Info
FileVersion:
Comments: This installation was built with Inno Setup.
CompanyName:
Translation: 0x0409 0x04e4

Malware-Cryptor.MTA also known as:

K7AntiVirusTrojan ( 0040f4e11 )
DrWebTrojan.Fakealert.37412
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.21540
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.8171
K7GWTrojan ( 0040f4e11 )
Cybereasonmalicious.31ea86
SymantecTrojan.FakeAV
ESET-NOD32Win32/Adware.SystemSecurity.AL
APEXMalicious
AvastWin32:FakeAV-ETD [Trj]
ClamAVWin.Trojan.Generickdz-9763206-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.21540
NANO-AntivirusTrojan.Win32.Fakealert.bwdffv
MicroWorld-eScanTrojan.GenericKDZ.21540
TencentWin32.Trojan.Generic.Lkxk
Ad-AwareTrojan.GenericKDZ.21540
SophosMal/Generic-S
ComodoTrojWare.Win32.FakeAV.ALM@4ykx3g
VIPRETrojan.Win32.Fakeav.qvsm (v)
TrendMicroTROJ_RANSOM.SM04
McAfee-GW-EditionFake-SecTool!3B5003731EA8
FireEyeGeneric.mg.3b5003731ea8603c
EmsisoftTrojan.GenericKDZ.21540 (B)
AviraHEUR/AGEN.1101523
eGambitUnsafe.AI_Score_99%
MicrosoftRogue:Win32/Winwebsec
ArcabitTrojan.Generic.D5424
GDataTrojan.GenericKDZ.21540
AhnLab-V3Trojan/Win32.FakeAV.R70710
McAfeeFake-SecTool!3B5003731EA8
MAXmalware (ai score=84)
VBA32Malware-Cryptor.MTA
MalwarebytesMalware.AI.1024959568
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_RANSOM.SM04
RisingTrojan.Generic@ML.98 (RDML:NFUDYMKheL8dtTyVcsly5A)
YandexTrojan.Agent!YvtUkQQlkGI
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.AL!tr
AVGWin32:FakeAV-ETD [Trj]
Paloaltogeneric.ml

How to remove Malware-Cryptor.MTA?

Malware-Cryptor.MTA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment