Ransom

About “Ransom:MSIL/FileCryptor.AA!MTB” infection

Malware Removal

The Ransom:MSIL/FileCryptor.AA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/FileCryptor.AA!MTB virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine Ransom:MSIL/FileCryptor.AA!MTB?


File Info:

crc32: DA657F40
md5: 5424f4bc6d709a58ecd1157f8c9d974a
name: 5424F4BC6D709A58ECD1157F8C9D974A.mlw
sha1: 7df95bc6c58672744c1c5563a1c57eceec2ccb44
sha256: 87a92bd93f41f3ea8e42bc6ae823543469abc5962806c59a761156d946699e74
sha512: cc94d7f7452bcd19d81ad169def9553979394aa02bd80b244eec1cb2a95e05e882471d252d473e07791a67d5ab594f20408207324ab9d1ef34e359ec1db91774
ssdeep: 3072:zELmLMamFHsna92ysl36kfeApaLzN1On6YLndodwVLsjxx8iJSjKnq7hLSyZwAT:zgaN5a92MkfbgOpLKdFP+KqFLSyZXKI
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: FaggotWare.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: FaggotWare
ProductVersion: 1.0.0.0
FileDescription: FaggotWare
OriginalFilename: FaggotWare.exe

Ransom:MSIL/FileCryptor.AA!MTB also known as:

K7AntiVirusTrojan ( 700000121 )
CynetMalicious (score: 85)
ALYacTrojan.Ransom.FileCryptor
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.5145
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:MSIL/FileCryptor.e6b4ace5
K7GWTrojan ( 700000121 )
Cybereasonmalicious.c6d709
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Filecoder.GY
APEXMalicious
AvastMSIL:Filecoder-AT [Trj]
KasperskyTrojan-Ransom.MSIL.Agent.yz
BitDefenderGeneric.Ransom.Hiddentear.A.74114E3C
NANO-AntivirusTrojan.Win32.FileCoder.epsusb
MicroWorld-eScanGeneric.Ransom.Hiddentear.A.74114E3C
TencentMsil.Trojan.Agent.Stai
Ad-AwareGeneric.Ransom.Hiddentear.A.74114E3C
ComodoMalware@#1zg0xcbq4xp71
BitDefenderThetaGen:NN.ZemsilF.34608.lm0@aKuCRr
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_XORGOT.A
McAfee-GW-EditionRDN/Ransom
FireEyeGeneric.Ransom.Hiddentear.A.74114E3C
EmsisoftGeneric.Ransom.Hiddentear.A.74114E3C (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/FileCoder.lnsov
MicrosoftRansom:MSIL/FileCryptor.AA!MTB
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Ransom.MSIL.Agent.yz
GDataGeneric.Ransom.Hiddentear.A.74114E3C
AhnLab-V3Trojan/Win32.Agent.C2056146
McAfeeRDN/Ransom
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_XORGOT.A
RisingRansom.Agent!8.6B7 (CLOUD)
YandexTrojan.Filecoder!E3Q8QYHg0pU
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.74701980.susgen
FortinetMSIL/Filecoder.TA!tr
AVGMSIL:Filecoder-AT [Trj]
Qihoo-360Win32/Ransom.HiddenTear.HgIASOoA

How to remove Ransom:MSIL/FileCryptor.AA!MTB?

Ransom:MSIL/FileCryptor.AA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment