Ransom

Ransom:MSIL/SamCrypter.PA!MTB removal guide

Malware Removal

The Ransom:MSIL/SamCrypter.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/SamCrypter.PA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to modify desktop wallpaper
  • Writes a potential ransom message to disk

How to determine Ransom:MSIL/SamCrypter.PA!MTB?


File Info:

crc32: 5A683C84
md5: dd3d20cd1413b35748ae1ccac4e05e35
name: DD3D20CD1413B35748AE1CCAC4E05E35.mlw
sha1: 4bdc78426a380664e983da23689299e6ca52d73f
sha256: e818ad6404a960f99d94419e7067be47fd100ddbab89046be6b2ab4e4fae6521
sha512: 8ed687f171135473bcb1b107d480d50f9667e11aae40683d3613095ecc56bb47e77f8f330f1ed0cd247944e967dccd182d8c02717af0853bfddb43fd869f8718
ssdeep: 384:zz0LmZ7N75okv5928hCLKrV5/NUeo98kloFkHQWoD1IvyvL2GE7gdP:zzCyN5ocVoYw98ooC3oD1dviGE7gdP
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: dlihost.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: dlihost.exe

Ransom:MSIL/SamCrypter.PA!MTB also known as:

K7AntiVirusTrojan ( 005748c91 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.HiddenTear
CylanceUnsafe
ZillyaTrojan.DelShad.Win32.925
SangforRansom.MSIL.SamCrypter.PA
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRansom:MSIL/SamCrypter.837ef0c7
K7GWTrojan ( 005748c91 )
Cybereasonmalicious.d1413b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/LockScreen.AJF
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.MSIL.DelShad.gen
BitDefenderGeneric.Ransom.Hiddentear.A.315FCF88
NANO-AntivirusTrojan.Win32.DelShad.ihsblb
MicroWorld-eScanGeneric.Ransom.Hiddentear.A.315FCF88
Ad-AwareGeneric.Ransom.Hiddentear.A.315FCF88
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34628.cm0@ayPSkCc
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_SamCrypter.R03BC0DA221
McAfee-GW-EditionBehavesLike.Win32.Generic.pz
FireEyeGeneric.mg.dd3d20cd1413b357
EmsisoftGeneric.Ransom.Hiddentear.A.315FCF88 (B)
AviraTR/LockScreen.hvbpv
eGambitUnsafe.AI_Score_85%
MicrosoftRansom:MSIL/SamCrypter.PA!MTB
ArcabitGeneric.Ransom.Hiddentear.A.315FCF88
AegisLabTrojan.MSIL.DelShad.4!c
GDataGeneric.Ransom.Hiddentear.A.315FCF88
AhnLab-V3Malware/Win32.RL_Generic.C4295161
McAfeeGenericRXNG-SY!DD3D20CD1413
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesRansom.HiddenTear
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_SamCrypter.R03BC0DA221
RisingRansom.DelShad!8.118FF (CLOUD)
IkarusTrojan.MSIL.LockScreen
MaxSecureTrojan.Malware.74133646.susgen
FortinetMSIL/Filecoder.5AE6!tr.ransom
AVGWin32:Trojan-gen
Qihoo-360Win32/Ransom.HiddenTear.HwMAsIYA

How to remove Ransom:MSIL/SamCrypter.PA!MTB?

Ransom:MSIL/SamCrypter.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment