Ransom

Ransom.PadCrypt.20 removal

Malware Removal

The Ransom.PadCrypt.20 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.PadCrypt.20 virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ransom.PadCrypt.20?


File Info:

crc32: D05E0422
md5: 11d66646d0542269a034f93b88dc5e77
name: 11D66646D0542269A034F93B88DC5E77.mlw
sha1: 84b389ab01b677102423168daabad38cbfaf6364
sha256: 9afc08796a7e70c7254fe0421308baae3237ba36775a07b5f210146370b3b52b
sha512: dc6368387b1efd27c3bd6718c16ab1571f80daeaae286c77b5e04739858ed3047eef0579c1432fd03349050cfbfa52fe1c5302180d5f2b8caf3b7b1e07519a85
ssdeep: 12288:ILCMimNzfwSk1fIZp8NBo4UgxDASDcuXL3PICtJ:cIp1c8NBolgBdDfb3
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 11.37.0.0
InternalName: ptsks.exe
FileVersion: 11.37.0.0
CompanyName: Microsoft Corporation
LegalTrademarks:
Comments:
ProductName: Microsoft
ProductVersion: 11.37.0.0
FileDescription: Windows Driver Service
OriginalFilename: ptsks.exe

Ransom.PadCrypt.20 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.10310
MicroWorld-eScanGen:Variant.Ransom.PadCrypt.20
FireEyeGeneric.mg.11d66646d0542269
CAT-QuickHealTrojan.Generic
Qihoo-360HEUR/QVM03.0.8E5B.Malware.Gen
McAfeeGenericRXBC-MI!11D66646D054
MalwarebytesTrojan.Dropper
SUPERAntiSpywareRansom.Cryptor/Variant
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Ransom.PadCrypt.20
K7GWTrojan ( 700000121 )
Cybereasonmalicious.6d0542
BitDefenderThetaGen:NN.ZemsilF.34590.Sn1@aScl!oi
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareGen:Variant.Ransom.PadCrypt.20
SophosML/PE-A
F-SecureTrojan.TR/FileCoder.bzuyf
TrendMicroRansom_CRYDAP.SMQ
McAfee-GW-EditionGenericRXBC-MI!11D66646D054
EmsisoftGen:Variant.Ransom.PadCrypt.20 (B)
IkarusTrojan.MSIL.Filecoder
JiangminTrojan.Generic.fwuix
AviraTR/FileCoder.bzuyf
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ransom.PadCrypt.20
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.PadCrypt.20
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Bayrob.C1899091
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=86)
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Filecoder.PadCrypt.F
TrendMicro-HouseCallRansom_CRYDAP.SMQ
RisingRansom.FileCryptor!8.1A7 (TFE:D:FWEylpUZLdB)
YandexTrojan.Agent!wNcfgF3Lh1k
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Generic.AP.9D47C!tr
AVGMSIL:Ransom-N [Trj]
AvastMSIL:Ransom-N [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom.PadCrypt.20?

Ransom.PadCrypt.20 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment