Ransom

What is “Ransom:MSIL/OsnoCrypt.MB!MTB”?

Malware Removal

The Ransom:MSIL/OsnoCrypt.MB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/OsnoCrypt.MB!MTB virus can do?

  • Anomalous binary characteristics

How to determine Ransom:MSIL/OsnoCrypt.MB!MTB?


File Info:

crc32: B302966F
md5: 9884bc4b00d1668f52e5e91b4c2dd3b3
name: upload_file
sha1: 04c8ce2599ac9f0a0124b39b040bf0c0fee26931
sha256: 3348af4619e431184873847593adb6da058b4ab91bc2cfc37003f8ba3c000f41
sha512: 76757394bca1ff2fb4fb9deaf92a660253f83483f6f500517627165f373201d6e3c31597867e835cc0606849bbfa28e8f0d68d1f985c4b082f913d81b5b27f72
ssdeep: 12288:KAAm9dcktIQAR7tPHzQ2OGoxEKRZgHSVy3g7tPHzGcW:KxcNI9R70hxRZyur7Q9
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Osno Corporation. All rights reserved. 2020
Assembly Version: 6.1.7601.17514
InternalName: Osno.exe
FileVersion: 6.1.7601.17514
CompanyName:
LegalTrademarks:
Comments:
ProductName: Osno Project
ProductVersion: 6.1.7601.17514
FileDescription: Osno Project
OriginalFilename: Osno.exe

Ransom:MSIL/OsnoCrypt.MB!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43992759
CAT-QuickHealTrojan.Wacatac
McAfeeRDN/Generic PWS.y
AegisLabTrojan.Win32.Malicious.4!c
K7AntiVirusSpyware ( 004c76c01 )
BitDefenderTrojan.GenericKD.43992759
K7GWSpyware ( 004c76c01 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D29F46B7
InvinceaMal/Generic-S
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallRansom.Win32.OSNO.THJOFBO
Paloaltogeneric.ml
AlibabaRansom:MSIL/OsnoCrypt.a640895f
Ad-AwareTrojan.GenericKD.43992759
EmsisoftTrojan.GenericKD.43992759 (B)
ComodoHeur.Corrupt.PE@1z141z3
F-SecureHeuristic.HEUR/AGEN.1109526
DrWebTrojan.PWS.Stealer.29333
TrendMicroRansom.Win32.OSNO.THJOFBO
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
SentinelOneDFI – Malicious PE
FireEyeGeneric.mg.9884bc4b00d1668f
APEXMalicious
AviraHEUR/AGEN.1109526
MicrosoftRansom:MSIL/OsnoCrypt.MB!MTB
AhnLab-V3Malware/Win32.Generic.C2852613
GDataTrojan.GenericKD.43992759
CynetMalicious (score: 85)
ALYacTrojan.Ransom.Filecoder
VBA32TrojanPSW.Stealer
MalwarebytesSpyware.Stealer
PandaTrj/CI.A
RisingRansom.OnyxLocker!1.C0BA (CLASSIC)
eGambitTrojan.Generic
FortinetMalicious_Behavior.SB
MaxSecureTrojan.Malware.300983.susgen

How to remove Ransom:MSIL/OsnoCrypt.MB!MTB?

Ransom:MSIL/OsnoCrypt.MB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment