Ransom

About “Ransom:MSIL/Natiris.A” infection

Malware Removal

The Ransom:MSIL/Natiris.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/Natiris.A virus can do?

  • Anomalous binary characteristics

How to determine Ransom:MSIL/Natiris.A?


File Info:

crc32: 42D3E90A
md5: db83c22b82e32a5f1b567b5d0d403bd8
name: DB83C22B82E32A5F1B567B5D0D403BD8.mlw
sha1: 80bea5e7c48ce6badb96d7c322618c050d42dd54
sha256: 93806a0981e6bc3d1c73b7796f8adc73e450e13c5afc7e21181aca0597c67ce3
sha512: 2caa0b8346be95db8d7356f5877e8df404535376952119ea34c0d5a634027b12f190c6220920b6576465ddd74a1ae636e3507f6405326f8e238c1e785e49995b
ssdeep: 1536:eTx6lw9pEHb+k0X+nPOnRQOlC4pXM69kAQ:wx6O9pubj0XOyRZ7hM2Q
type: MS-DOS executable, MZ for MS-DOS

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: KristinaCS.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: crypt12
ProductVersion: 1.0.0.0
FileDescription: crypt12
OriginalFilename: KristinaCS.exe

Ransom:MSIL/Natiris.A also known as:

K7AntiVirusTrojan ( 005206081 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Crypt12
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7515
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:MSIL/Natiris.64719a3f
K7GWTrojan ( 005206081 )
Cybereasonmalicious.b82e32
SymantecW32.Ramnit!dr
ESET-NOD32a variant of MSIL/Filecoder.Crypt12.A
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.CryptTwelve.4BE98A55
NANO-AntivirusTrojan.Win32.FileCoder.evymrq
MicroWorld-eScanGeneric.Ransom.CryptTwelve.4BE98A55
TencentWin32.Trojan.Generic.Wtnf
Ad-AwareGeneric.Ransom.CryptTwelve.4BE98A55
SophosMal/Generic-R + Mal/Krypt12-B
ComodoMalware@#2dtjpo5kshi6i
BitDefenderThetaGen:NN.ZemsilF.34628.dm3@a4xOSwh
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.cwi
FireEyeGeneric.mg.db83c22b82e32a5f
EmsisoftGeneric.Ransom.CryptTwelve.4BE98A55 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.NanoBot.b
AviraTR/FileCoder.zxrko
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:MSIL/Natiris.A
ArcabitGeneric.Ransom.CryptTwelve.4BE98A55
AegisLabTrojan.Win32.Generic.4!c
GDataGeneric.Ransom.CryptTwelve.4BE98A55
McAfeeGeneric.cwi
MAXmalware (ai score=97)
PandaTrj/CI.A
RisingVirus.Ramnit!8.4 (CLOUD)
YandexTrojan.Agent!PA2ZqfXn7j8
IkarusTrojan-Ransom.FileCrypter
FortinetMSIL/Filecoder_Crypt12.A!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HgIASOgA

How to remove Ransom:MSIL/Natiris.A?

Ransom:MSIL/Natiris.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment