Ransom

Ransom:Win32/Dopplepaymer.KM!MTB malicious file

Malware Removal

The Ransom:Win32/Dopplepaymer.KM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Dopplepaymer.KM!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Dopplepaymer.KM!MTB?


File Info:

crc32: 974974D5
md5: 76492635036b465bca44da7ec8775511
name: 76492635036B465BCA44DA7EC8775511.mlw
sha1: 301d3b7eaf703d8ebcbed0fd3f6422f6791c635f
sha256: 15098c42f52c40ff4c4b78d2007c103f6637020774062c48d6079e7344a44c6f
sha512: a393575cacf88516450f851e8e2991dab6c88be12baf3d0a8378bd51cead9a85b3a3cfaa846e2a8d6d1d7833b8cae627a896d20af107d51b91a7bd6e4bdef2d2
ssdeep: 6144:6LMD6U18+P94did4uwrh6vwhCxgOvYNwuYmbDx:LDI+P9wid6QwCZvYNRYmR
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2003-2006, Sebastian Andersson
FileDescription: Musepack add-on for the BASS library
FileVersion: 2.4.1.2
CompanyName: MaresWEB
Translation: 0x0000 0x04b0

Ransom:Win32/Dopplepaymer.KM!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.667554
FireEyeGeneric.mg.76492635036b465b
McAfeeGenericRXKK-WZ!76492635036B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Razy.667554
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5036b4
SymantecPacked.Generic.553
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Zenpak.vho
AlibabaRansom:Win32/Dopplepaymer.502ed025
NANO-AntivirusTrojan.Win32.Zenpak.imgabv
RisingRansom.Dopplepaymer!8.1148E (CLOUD)
Ad-AwareGen:Variant.Razy.667554
EmsisoftGen:Variant.Razy.667554 (B)
F-SecureTrojan.TR/Crypt.Agent.qtxbn
ZillyaTrojan.Kryptik.Win32.2013532
McAfee-GW-EditionGenericRXKK-WZ!76492635036B
SophosML/PE-A
IkarusTrojan-Ransom.Enestedel
JiangminTrojan.Zenpak.brd
AviraTR/Crypt.Agent.qtxbn
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Zenpak
MicrosoftRansom:Win32/Dopplepaymer.KM!MTB
GridinsoftTrojan.Win32.Kryptik.ba!s1
ArcabitTrojan.Razy.DA2FA2
ZoneAlarmHEUR:Trojan.Win32.Zenpak.vho
GDataGen:Variant.Razy.667554
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R367173
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.nC0@auDL8qhG
ALYacGen:Variant.Razy.667554
VBA32Trojan.Wacatac
MalwarebytesTrojan.Dridex
ESET-NOD32a variant of Win32/Kryptik.HDEJ
YandexTrojan.Kryptik!SSip246nQJs
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HHVS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Zenpak.HxMBbJsA

How to remove Ransom:Win32/Dopplepaymer.KM!MTB?

Ransom:Win32/Dopplepaymer.KM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment