Ransom

Ransom:MSIL/RozbehCrypt!MTB information

Malware Removal

The Ransom:MSIL/RozbehCrypt!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/RozbehCrypt!MTB virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Ransom:MSIL/RozbehCrypt!MTB?


File Info:

name: B0F58F205BD28539A143.mlw
path: /opt/CAPEv2/storage/binaries/53fa47f66d92dc1cbcddf65a0f34701e8e7fafe2836460777d4bb35f89f06f5b
crc32: 09D711FB
md5: b0f58f205bd28539a1435bc6b6cf5955
sha1: 97ff3ab373d51d52fd44365ff7e0abfc6511d24f
sha256: 53fa47f66d92dc1cbcddf65a0f34701e8e7fafe2836460777d4bb35f89f06f5b
sha512: 518052201b21ac10342161c95c0eb89b22808a03375ac58d2de4e96a85f784ac79b55dc5f29ccc2a9d8b3095217442a085e1eb6b4e5c58fde5df6cd8a6e856ab
ssdeep: 24576:Toooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooon:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105D6B90C63988526F0FF8739AD762640A370F697D837476F258EA21F6F3275049D2B62
sha3_384: fb6a923b2bfa7aefac2846fdfc63b14e020d26dd040be43570b79622da48e60e10293a62aec5822cb1ec5aab69845bd6
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-11 06:48:32

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Virus.win32RozbehStrike
FileVersion: 1.0.8076.41056
InternalName: Virus.win32RozbehStrike.exe
LegalCopyright: Copyright 2022
OriginalFilename: Virus.win32RozbehStrike.exe
ProductName: Virus.win32RozbehStrike
ProductVersion: 1.0.8076.41056
Assembly Version: 1.0.8076.41056

Ransom:MSIL/RozbehCrypt!MTB also known as:

MicroWorld-eScanTrojan.Ransom.GenericKD.48338494
FireEyeGeneric.mg.b0f58f205bd28539
McAfeeGenericRXRT-NV!B0F58F205BD2
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058e55f1 )
K7GWTrojan ( 0058e55f1 )
Cybereasonmalicious.373d51
BitDefenderThetaGen:NN.ZemsilCO.34606.@p3@a0R2aAd
VirITTrojan.Win32.Generic.YKY
CyrenW32/MSIL_Troj.BZA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Filecoder.AOH
KasperskyTrojan-Ransom.Win32.Encoder.ptm
BitDefenderTrojan.Ransom.GenericKD.48338494
NANO-AntivirusTrojan.Win32.Encoder.jmvddp
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.Ransom.GenericKD.48338494
EmsisoftTrojan.Ransom.GenericKD.48338494 (B)
DrWebTrojan.Encoder.35032
ZillyaTrojan.Filecoder.Win32.22484
TrendMicroRansom.MSIL.ROZBEHCRYPT.SMYXCCV
McAfee-GW-EditionBehavesLike.Win32.Generic.rt
SophosML/PE-A
APEXMalicious
JiangminTrojan.Encoder.aqz
AviraTR/Ransom.micjx
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.352B89B
MicrosoftRansom:MSIL/RozbehCrypt!MTB
ZoneAlarmTrojan-Ransom.Win32.Encoder.ptm
GDataTrojan.Ransom.GenericKD.48338494
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4968345
VBA32TScope.Trojan.MSIL
ALYacTrojan.Ransom.GenericKD.48338494
MalwarebytesTrojan.MultiDropper
TencentMalware.Win32.Gencirc.11e960d4
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Filecoder.AOH!tr
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:MSIL/RozbehCrypt!MTB?

Ransom:MSIL/RozbehCrypt!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment