Ransom

Ransom:MSIL/FileCryptor.PL!MTB removal instruction

Malware Removal

The Ransom:MSIL/FileCryptor.PL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/FileCryptor.PL!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ransom:MSIL/FileCryptor.PL!MTB?


File Info:

crc32: C8A55A49
md5: 85b38fb1ae38cdc2b2b288b414e6f5c0
name: 85B38FB1AE38CDC2B2B288B414E6F5C0.mlw
sha1: 7a93bb4f2ef04d86d4cad2098860dcad13a775d2
sha256: 9a355fc10fe9e7906c34d8850a2efc5c93a3a1274ce3b122f5d6944b2d33f837
sha512: aa71f5b5dffe52e604ad2b4ab11577dc8cf7a365ece247abab8cf823da6f4af79419a5c35851462abfc22299edab68fc5f5ed043aa13c4a4805149a539d31a5d
ssdeep: 768:x/Ekga9ay2WpMvr8LEHOki2pELMU4XVtsFfF/TVVFXzJLVL3Hnc5tunpqKYhJ:YvyXQr8L7ki2pELMefdVVRDFnpqKmJ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: love.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: love.exe

Ransom:MSIL/FileCryptor.PL!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45103403
FireEyeTrojan.GenericKD.45103403
CAT-QuickHealTrojan.MsilFC.S18288100
Qihoo-360Win32/Trojan.Crypmod.HgIASOkA
ALYacTrojan.GenericKD.45103403
CylanceUnsafe
AegisLabTrojan.MSIL.Crypmod.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005751131 )
BitDefenderTrojan.GenericKD.45103403
K7GWTrojan ( 005751131 )
Cybereasonmalicious.1ae38c
BitDefenderThetaGen:NN.ZemsilF.34590.dm0@ayDkown
CyrenW32/Trojan.DTJO-3067
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Ransom.MSIL.Crypmod.gen
AlibabaRansom:MSIL/FileCryptor.ecf6751c
NANO-AntivirusTrojan.Win32.Ransom.ikkhjc
RisingTrojan.Filecoder!8.68 (CLOUD)
Ad-AwareTrojan.GenericKD.45103403
SophosMal/Generic-S
F-SecureTrojan.TR/Ransom.zlvnx
ZillyaTrojan.Filecoder.Win32.17325
TrendMicroRansom.MSIL.POVLSOM.THBAOBA
McAfee-GW-EditionRDN/Ransom
EmsisoftTrojan.GenericKD.45103403 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Ransom.zlvnx
Antiy-AVLTrojan[Ransom]/MSIL.Crypmod
MicrosoftRansom:MSIL/FileCryptor.PL!MTB
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Generic.D2B0392B
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Crypmod.gen
GDataTrojan.GenericKD.45103403
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4277604
McAfeeRDN/Ransom
MAXmalware (ai score=88)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.204912702
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Filecoder.ADX
TrendMicro-HouseCallRansom.MSIL.POVLSOM.THBAOBA
TencentMalware.Win32.Gencirc.11b807d1
YandexTrojan.Filecoder!AW0xXTWCc/0
IkarusTrojan-Ransom.FileCrypter
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Filecoder.410F!tr.ransom
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.73703920.susgen

How to remove Ransom:MSIL/FileCryptor.PL!MTB?

Ransom:MSIL/FileCryptor.PL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment