Ransom

Ransom:Win32/Avaddon.MK!MTB (file analysis)

Malware Removal

The Ransom:Win32/Avaddon.MK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Avaddon.MK!MTB virus can do?

  • Anomalous binary characteristics

How to determine Ransom:Win32/Avaddon.MK!MTB?


File Info:

crc32: 9545B99E
md5: 6fac91349f1e3171384e2c4e51814a5a
name: upload_file
sha1: 9a11a620c835f1bc8ac527a48f7c5d0443aaa9df
sha256: f25bac7d622cd257c9668067e7499c0587e14f5c9719177df836c0778a420ee2
sha512: b8cbb6c4efad681b99e9f555b27cdd2ea4a84c1965ca51a8c228f9ff6ff36563b4fde73d15ecbd9903ceca3a4e6f142a4b45af78d5d120e349d2967d1592298d
ssdeep: 98304:bw3OKBzMFxybbbbpNGWeEi4DtrRKm40dC:bw3y6bbbbpNYwDdC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: taskhost.exe
FileVersion: 10.0.17763.831 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.17763.831
FileDescription: Host Process for Windows Tasks
OriginalFilename: taskhost.exe
Translation: 0x0409 0x04b0

Ransom:Win32/Avaddon.MK!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34435700
FireEyeGeneric.mg.6fac91349f1e3171
McAfeeGenericRXLO-WC!6FAC91349F1E
BitDefenderTrojan.GenericKD.34435700
Cybereasonmalicious.0c835f
APEXMalicious
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.34435700
DrWebTrojan.Encoder.32315
ZillyaTrojan.DelShad.Win32.594
McAfee-GW-EditionBehavesLike.Win32.Suspect.wh
EmsisoftTrojan.GenericKD.34435700 (B)
IkarusTrojan-Ransom.Avaddon
MAXmalware (ai score=88)
MicrosoftRansom:Win32/Avaddon.MK!MTB
ArcabitTrojan.Generic.D20D7274
GDataTrojan.GenericKD.34435700
ALYacTrojan.GenericKD.34435700
MalwarebytesRansom.Avaddon
RisingRansom.Avaddon!8.11C4D (TFE:5:czMCsQMNsYG)
SentinelOneDFI – Malicious PE
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom:Win32/Avaddon.MK!MTB?

Ransom:Win32/Avaddon.MK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment