Ransom

Ransom.Mbro.16920 malicious file

Malware Removal

The Ransom.Mbro.16920 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Mbro.16920 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Mbro.16920?


File Info:

crc32: EE5A10C5
md5: e48ccb594c76749d234867696b365d4a
name: E48CCB594C76749D234867696B365D4A.mlw
sha1: fa1e8044151f715a049814d04d4c206eac1c7472
sha256: 02f33cd5e39f62efb2ee536d7b27d13f477bb6380c8c593d4e74f12abb3522fd
sha512: 03d7d38df533821a4852ad00fa1259094a75c2ab20d6a2fd4d58484488ceb818a525fa4799c391b5eb3863c4ce9cd1a8740d52e339da658b7da391e8b2c07a12
ssdeep: 12288:vGqgH43w3/HK42fH0Y7RMKVQ/qodoScXwxnrLypW4eSs1k2s5YqK7wkG:j3S/Hh2fUSRFQRoScXwLaeSsQY9sx
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Ransom.Mbro.16920 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Mbro.j!c
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.6
CAT-QuickHealRansom.Mbro.16920
CylanceUnsafe
ZillyaTrojan.Mbro.Win32.4778
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004d4a2d1 )
K7AntiVirusTrojan ( 004d4a2d1 )
CyrenW32/Ransom.X.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MBRlock.R
APEXMalicious
AvastMBR:Ransom-A [Rtk]
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Mbro.rv
NANO-AntivirusTrojan.Win32.Mbro.cvhnvk
TencentWin32.Trojan.Mbro.Ajvg
SophosMal/Generic-S
ComodoMalware@#2lbalds11c7lq
BitDefenderThetaAI:Packer.5D441D781E
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_RANSOM_BL13015C.TOMC
McAfee-GW-EditionBehavesLike.Win32.Injector.jc
FireEyeGeneric.mg.e48ccb594c76749d
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.RemoteManipulator.cg
AviraBOO/Ransom.AB
MicrosoftRansom:Win32/Genasom
ZoneAlarmTrojan-Ransom.Boot.Mbro.d
McAfeeArtemis!E48CCB594C76
MAXmalware (ai score=100)
VBA32Trojan.Ransom.5705
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_RANSOM_BL13015C.TOMC
RisingRansom.MBRlock!1.66BD (CLASSIC)
YandexTrojan.GenAsa!Gjvmir2oDNE
IkarusTrojan-Downloader.Win32.VB.aco
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/MBro.R!tr
AVGMBR:Ransom-A [Rtk]
Paloaltogeneric.ml

How to remove Ransom.Mbro.16920?

Ransom.Mbro.16920 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment