Ransom

What is “Ransom:MSIL/CobraLocker.DC!MTB”?

Malware Removal

The Ransom:MSIL/CobraLocker.DC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/CobraLocker.DC!MTB virus can do?

    How to determine Ransom:MSIL/CobraLocker.DC!MTB?

    
    

    File Info:

    crc32: 56803CD8
    md5: a753f1713f0654c40eee6d4869dba581
    name: A753F1713F0654C40EEE6D4869DBA581.mlw
    sha1: 3eafa98898f9d5478a1572c1f97cf89744f48479
    sha256: 92e181b681bf9068db58c82f23d2e01b7a93fbec4be150bd1416dd43f27e151c
    sha512: d93a5be35ca46ec7e439572446120178b511c98d63ba66f64222a9d9cd353c774c5dc3d4e47725538599e275f2de115c1d7afd30e816c66c41bce0786af386b5
    ssdeep: 768:q4O9YoLakVLmHXnlLKAX/bJ7zOQk4JL2x2LI6RMJyGmYFtX7A1B1OgpQg7/bPYc:q4ijVVLyki1E40x2NR6BtrA1sg/uV1
    type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

    Version Info:

    Translation: 0x0000 0x04b0
    LegalCopyright: Copyright xa9 2020
    Assembly Version: 1.0.0.0
    InternalName: Cobra_Locker.exe
    FileVersion: 1.0.0.0
    CompanyName:
    LegalTrademarks:
    Comments:
    ProductName: Cobra_Locker
    ProductVersion: 1.0.0.0
    FileDescription: Cobra_Locker
    OriginalFilename: Cobra_Locker.exe

    Ransom:MSIL/CobraLocker.DC!MTB also known as:

    K7AntiVirusTrojan ( 005761051 )
    Elasticmalicious (high confidence)
    CynetMalicious (score: 100)
    CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
    ALYacTrojan.Ransom.Filecoder
    CylanceUnsafe
    ZillyaTrojan.Filecoder.Win32.17594
    SangforTrojan.Win32.Save.a
    CrowdStrikewin/malicious_confidence_90% (W)
    AlibabaRansom:MSIL/CobraLocker.e8b188bf
    K7GWTrojan ( 005761051 )
    Cybereasonmalicious.13f065
    SymantecML.Attribute.HighConfidence
    ESET-NOD32a variant of MSIL/Filecoder.CobraLocker.B
    APEXMalicious
    AvastWin32:MalwareX-gen [Trj]
    KasperskyHEUR:Trojan-Ransom.MSIL.Encoder.gen
    BitDefenderGen:Variant.Razy.820272
    NANO-AntivirusTrojan.Win32.Ransom.ikuout
    MicroWorld-eScanGen:Variant.Razy.820272
    TencentMsil.Trojan.Encoder.Lmal
    Ad-AwareGen:Variant.Razy.820272
    SophosMal/Generic-S
    ComodoMalware@#3mh1x816iy5q0
    BitDefenderThetaGen:NN.ZemsilF.34628.jm0@a01DV9j
    VIPRETrojan.Win32.Generic!BT
    TrendMicroRansom.MSIL.COBRALOCKER.SMC
    McAfee-GW-EditionRDN/Ransom
    FireEyeGeneric.mg.a753f1713f0654c4
    EmsisoftTrojan.FileCoder (A)
    SentinelOneStatic AI – Malicious PE
    WebrootW32.Trojan.Gen
    AviraHEUR/AGEN.1112868
    eGambitUnsafe.AI_Score_99%
    MicrosoftRansom:MSIL/CobraLocker.DC!MTB
    ArcabitTrojan.Razy.DC8430
    AegisLabTrojan.MSIL.Encoder.j!c
    GDataGen:Variant.Razy.820272
    AhnLab-V3Malware/Win32.RL_Generic.C4282413
    McAfeeRDN/Ransom
    MAXmalware (ai score=87)
    MalwarebytesRansom.CobraLocker
    PandaTrj/GdSda.A
    TrendMicro-HouseCallRansom.MSIL.COBRALOCKER.SMC
    RisingTrojan.Filecoder!8.68 (CLOUD)
    IkarusTrojan-Ransom.FileCrypter
    FortinetMSIL/Filecoder.95D4!tr.ransom
    AVGWin32:MalwareX-gen [Trj]
    Paloaltogeneric.ml
    Qihoo-360Win32/Ransom.Cobra.HgIASQIA

    How to remove Ransom:MSIL/CobraLocker.DC!MTB?

    Ransom:MSIL/CobraLocker.DC!MTB removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment