Ransom

Ransom:MSIL/Penta.A!MTB removal instruction

Malware Removal

The Ransom:MSIL/Penta.A!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/Penta.A!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ransom:MSIL/Penta.A!MTB?


File Info:

crc32: 4D03E40A
md5: 81f5893f673b81ed4a271634c899aed2
name: 81F5893F673B81ED4A271634C899AED2.mlw
sha1: 7ccd3b7434b908f060a56f90594fc3d46252113b
sha256: c230758a0b4389848b032ca8ef0fec581763c0ba51f49ff267d39ade19366ffd
sha512: 3a5350743d757e805d46a7d965032e24793cbe0a82e0c4b83ccc3de3ab9aab509faa8a66c3d44ccb53b76cba36d40f1c9eb8f7ad1325a2f244ec11e661cd636d
ssdeep: 768:Ln3kIsp+L5hSIr9ix4mZryx7L2ksQ1QC/KeX:z3kI3hSIr9ixsx32XK/HX
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: PENTA_RANSOMWARE.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: PENTA_RANSOMWARE.exe

Ransom:MSIL/Penta.A!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.ClipBankerNET.7
ClamAVWin.Ransomware.Hydracrypt-9878672-0
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
SangforTrojan.Win32.Save.a
CyrenW32/Azorult.D.gen!Eldorado
ESET-NOD32a variant of MSIL/Filecoder.AJE
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.MSIL.Agent.gen
BitDefenderGeneric.Ransom.HydraCrypt.3D8ED839
MicroWorld-eScanGeneric.Ransom.HydraCrypt.3D8ED839
Ad-AwareGeneric.Ransom.HydraCrypt.3D8ED839
SophosML/PE-A + Mal/Genasom-A
BitDefenderThetaGen:NN.ZemsilF.34142.dm0@aGaEVzh
McAfee-GW-EditionGenericRXPW-PH!81F5893F673B
FireEyeGeneric.mg.81f5893f673b81ed
EmsisoftTrojan-Ransom.Penta (A)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1138919
eGambitUnsafe.AI_Score_97%
MicrosoftRansom:MSIL/Penta.A!MTB
ArcabitGeneric.Ransom.HydraCrypt.3D8ED839
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Agent.gen
GDataMSIL.Trojan-Ransom.Remind.B
AhnLab-V3Ransomware/Win.FTD.C4580180
McAfeeGenericRXPW-PH!81F5893F673B
MAXmalware (ai score=85)
MalwarebytesRansom.FileCryptor
RisingRansom.Destructor!1.B060 (CLASSIC)
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.AGP!tr.ransom
AVGWin32:RansomX-gen [Ransom]

How to remove Ransom:MSIL/Penta.A!MTB?

Ransom:MSIL/Penta.A!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment