Ransom

Ransom:MSIL/Manamecrypt.A removal tips

Malware Removal

The Ransom:MSIL/Manamecrypt.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/Manamecrypt.A virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:MSIL/Manamecrypt.A?


File Info:

crc32: 71F2200A
md5: 97c6b28bb15c69984b6477e1d425d5d3
name: 97C6B28BB15C69984B6477E1D425D5D3.mlw
sha1: f6705591ae43a2928734c453829696af33c598bd
sha256: 5301e23320b4100b74831f05d4244b706969dd1899ef87dd41bca7cc7c914365
sha512: 4f264e89817a6642ef0b18bea64f809229e9c4de310537d462c8ec3230cc2d1f91915e45286316100599a8afa6a6b8d896e7f34b3c4c5d2a0594b2ebbd0726c7
ssdeep: 384:LptlRg0Y0+sgmR7ogcRuQaVso9/GrzvbSxek/3A4xFgBRTaAKWX:NuJ1slc5IjVJ9egAgKHBb
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2016
Assembly Version: 1.0.0.0
InternalName: mm.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: mm
ProductVersion: 1.0.0.0
FileDescription: mm
OriginalFilename: mm.exe

Ransom:MSIL/Manamecrypt.A also known as:

K7AntiVirusTrojan ( 00504f051 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10598
ALYacGeneric.Ransom.Hiddentear.A.5797E922
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.4165
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 00504f051 )
Cybereasonmalicious.bb15c6
SymantecInfostealer.Limitail
ESET-NOD32a variant of MSIL/Filecoder.AY
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.MSIL.Tear.cj
BitDefenderGeneric.Ransom.Hiddentear.A.5797E922
NANO-AntivirusTrojan.Win32.Ransom.elmyhi
MicroWorld-eScanGeneric.Ransom.Hiddentear.A.5797E922
TencentMsil.Trojan.Tear.Hvsw
Ad-AwareGeneric.Ransom.Hiddentear.A.5797E922
ComodoMalware@#vokluw5x7w3k
BitDefenderThetaGen:NN.ZemsilF.34670.bm0@aCUQ1kb
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_RAMSIL.SM
McAfee-GW-EditionRansomware-FTD!97C6B28BB15C
FireEyeGeneric.mg.97c6b28bb15c6998
EmsisoftGeneric.Ransom.Hiddentear.A.5797E922 (B)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:MSIL/Manamecrypt.A
AegisLabTrojan.Win32.Generic.4!c
GDataMSIL.Trojan-Ransom.Cryptear.H
McAfeeRansomware-FTD!97C6B28BB15C
MAXmalware (ai score=100)
VBA32Trojan-Ransom.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_RAMSIL.SM
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.Tear!4OP9PJk7/MA
IkarusTrojan.MSIL.Filecoder
FortinetMSIL/Filecoder.TA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.HiddenTear.HwMAdYUA

How to remove Ransom:MSIL/Manamecrypt.A?

Ransom:MSIL/Manamecrypt.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment