Ransom

Should I remove “Ransom:Win32/Egregor.UX!MTB”?

Malware Removal

The Ransom:Win32/Egregor.UX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Egregor.UX!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Ransom:Win32/Egregor.UX!MTB?


File Info:

name: 49A6FB8EE6A08459A404.mlw
path: /opt/CAPEv2/storage/binaries/7222c8acc69a7598989c335d528b366f801a41b434cbf928c6aef01f8e54f57a
crc32: 5013E372
md5: 49a6fb8ee6a08459a404b27f9e2b868b
sha1: 5da8a11917e18dbf81033f973c0a2f0d8854e43b
sha256: 7222c8acc69a7598989c335d528b366f801a41b434cbf928c6aef01f8e54f57a
sha512: 582813df63b71e1f831c37fa01c637fda501d32321d58da4d791e1c0305016dacca78e1c029c1e0d5e9fb79b8989f61239667501519b6ee64ad8fe34b9359257
ssdeep: 12288:TMM/++6FdtTCM6v/Z8lnoZMaor/OWMKnOg7mE:TMMWjeuoKasLOgq
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T16D05CF10788042F2C8EA20F947EC71B214ADB8F14B295EC756DC0AFFD9645D17B36B6A
sha3_384: f5cc0675dc2c1aedcbceea1147897cbf2d841e3a258c3293234e36571069a72d12805bcaa2a8fdfb5ec5180b829fb67b
ep_bytes: e9a8d60000e9d4040400e95be30100e9
timestamp: 2020-09-22 21:17:23

Version Info:

0: [No Data]

Ransom:Win32/Egregor.UX!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Egregor.j!c
ElasticWindows.Ransomware.Egregor
MicroWorld-eScanGen:Variant.Mikey.115731
SkyhighRansom-Egregor!49A6FB8EE6A0
ALYacTrojan.Ransom.Egregor
Cylanceunsafe
SangforRansom.Win32.Egregor.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Egregor.228de13f
K7GWTrojan ( 00569bea1 )
K7AntiVirusTrojan ( 00569bea1 )
ArcabitTrojan.Mikey.D1C413
BitDefenderThetaGen:NN.ZedlaF.36680.XC4@aOnSKHn
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HEDE
CynetMalicious (score: 100)
ClamAVWin.Ransomware.Egregor-9774521-0
KasperskyHEUR:Trojan-Ransom.Win32.Egregor.gen
BitDefenderGen:Variant.Mikey.115731
NANO-AntivirusTrojan.Win32.Egregor.hzspqk
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.10bdfd5f
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.fhkui
DrWebTrojan.Encoder.32897
VIPREGen:Variant.Mikey.115731
TrendMicroRansom.Win32.EGREGOR.SMYAAK-J
EmsisoftGen:Variant.Mikey.115731 (B)
IkarusTrojan-Ransom.Egregor
JiangminTrojan.Egregor.e
VaristW32/Kryptik.CGQ.gen!Eldorado
AviraTR/Redcap.fhkui
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Trojan-Ransom.Generic.a
MicrosoftRansom:Win32/Egregor.UX!MTB
ViRobotTrojan.Win32.S.Agent.809472.F
ZoneAlarmHEUR:Trojan-Ransom.Win32.Egregor.gen
GDataWin32.Trojan-Ransom.Egregor.A
GoogleDetected
AhnLab-V3Trojan/Win32.Cryptor.C4064147
McAfeeRansom-Egregor!49A6FB8EE6A0
TACHYONRansom/W32.Egregor.809472.B
VBA32TrojanRansom.Egregor
MalwarebytesMalware.AI.4179401798
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.EGREGOR.SMYAAK-J
RisingTrojan.Generic@AI.100 (RDML:IbPgp9xQWLtmg2n6QjBfHw)
YandexTrojan.Kryptik!0MgiuyXSJJA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.108856364.susgen
Fortinetunknown
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Ransom:Win32/Egregor.UX!MTB?

Ransom:Win32/Egregor.UX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment