Ransom

Ransom:Win32/CryptedAutoIt.S!MTB removal

Malware Removal

The Ransom:Win32/CryptedAutoIt.S!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/CryptedAutoIt.S!MTB virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/CryptedAutoIt.S!MTB?


File Info:

crc32: 8FDFAC0A
md5: 2ee20e06c12fe69b6ef8ee3aa8360b7e
name: 2EE20E06C12FE69B6EF8EE3AA8360B7E.mlw
sha1: 536a88f554b64c5d8794262b83871329299b49ac
sha256: 1e79e7ff68fe58700e95d339a169863bf2555cb0609c2333a766191f7326bea4
sha512: 1f45f026643cb480687799607f556be7aa90d369f7390ee4e55e621cf424ded630fc9eeef69f1389eae81f4827398be28978b39fb808d58840d038acabf404d1
ssdeep: 24576:gAHnh+eWsN3skA4RV1Hom2KXMmHaE1klj5:Xh+ZkldoPK8YaE1y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Ransom:Win32/CryptedAutoIt.S!MTB also known as:

K7AntiVirusTrojan ( 0053f9b61 )
CynetMalicious (score: 100)
ALYacGeneric.Ransom.KillRabit.1F03A3BF
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/CryptedAutoIt.77c47d03
K7GWTrojan ( 0053f9b61 )
Cybereasonmalicious.6c12fe
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Filecoder.Autoit.O
APEXMalicious
AvastScript:SNH-gen [Trj]
KasperskyTrojan-Ransom.Win32.Encoder.ikv
BitDefenderGeneric.Ransom.KillRabit.1F03A3BF
NANO-AntivirusTrojan.Win32.Filecoder.hjzevz
MicroWorld-eScanGeneric.Ransom.KillRabit.1F03A3BF
TencentWin32.Trojan.Encoder.Hwna
Ad-AwareGeneric.Ransom.KillRabit.1F03A3BF
SophosGeneric ML PUA (PUA)
ComodoMalware@#1lhwyj1v61j5k
BitDefenderThetaAI:Packer.866A1D7924
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.ch
FireEyeGeneric.mg.2ee20e06c12fe69b
EmsisoftGeneric.Ransom.KillRabit.1F03A3BF (B)
WebrootW32.Trojan.Gen
AviraTR/FileCoder.zxeic
eGambitUnsafe.AI_Score_95%
MicrosoftRansom:Win32/CryptedAutoIt.S!MTB
ArcabitGeneric.Ransom.KillRabit.1F03A3BF
AegisLabHacktool.Win32.Gamehack.3!e
GDataGeneric.Ransom.KillRabit.1F03A3BF (2x)
AhnLab-V3Malware/Win32.Generic.C4105899
McAfeeArtemis!2EE20E06C12F
MAXmalware (ai score=81)
VBA32TrojanRansom.Encoder
MalwarebytesMalware.AI.2399765874
PandaTrj/CI.A
IkarusTrojan-Ransom.Autoit
FortinetW32/Encoder.IKV!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml

How to remove Ransom:Win32/CryptedAutoIt.S!MTB?

Ransom:Win32/CryptedAutoIt.S!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment