Ransom

About “Ransom:Win32/ExciteRAN.SL!MTB” infection

Malware Removal

The Ransom:Win32/ExciteRAN.SL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/ExciteRAN.SL!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/ExciteRAN.SL!MTB?


File Info:

crc32: 28F30207
md5: ec288c82cd1f485d5df769df2e8e8d0a
name: EC288C82CD1F485D5DF769DF2E8E8D0A.mlw
sha1: e4623f663eb7469197854e34c0659348c63b9b0f
sha256: ddae1a3f05f7cd71cd0660c82580082031a4c4a322bb66db1608fb069333cd01
sha512: 22dd824cda4ed892908a4ff73bebe5b3efaf5f92d1220ca47575653707b9e8e3f1ae761bcddd67a4edf5ece2d27a5f9b40e8326b179c337245c88e4f217f7a56
ssdeep: 1536:87I/IDPXARpqQjUho9JdZ582YSV4yLbeW+0vxZwVcl:87I/IkRpJEo9JdZ5rYg4yLbegZqY
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: ExciteRAN.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Rasomware2.0
ProductVersion: 1.0.0.0
FileDescription: Rasomware2.0
OriginalFilename: ExciteRAN.exe

Ransom:Win32/ExciteRAN.SL!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33357
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
FireEyeGen:Heur.Ransom.REntS.Gen.1
CAT-QuickHealTrojan.MsilFC.S17872831
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Filecoder.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057146f1 )
BitDefenderGen:Heur.Ransom.REntS.Gen.1
K7GWTrojan ( 0057146f1 )
Cybereasonmalicious.2cd1f4
BitDefenderThetaGen:NN.ZemsilF.34574.jm0@aqQ2W7k
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Ransom.MSIL.Encoder.vho
AlibabaRansom:Win32/ExciteRAN.5d00f69a
ViRobotTrojan.Win32.Z.Filecoder.152576
RisingRansom.Agent!1.CE87 (CLASSIC)
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
SophosMal/Generic-R + Mal/Cryptear-A
ComodoTrojWare.Win32.Agent.kkpeh@0
F-SecureHeuristic.HEUR/AGEN.1137051
ZillyaTrojan.Filecoder.Win32.17401
TrendMicroRansom_ExciteRAN.R004C0DLU20
McAfee-GW-EditionGenericRXMR-RG!EC288C82CD1F
EmsisoftTrojan.FileCoder (A)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1137051
MAXmalware (ai score=100)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/ExciteRAN.SL!MTB
GridinsoftRansom.Win32.Filecoder.sd!ni
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Encoder.vho
GDataGen:Heur.Ransom.REntS.Gen.1
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.RL_Ransom.C4212291
McAfeeGenericRXMR-RG!EC288C82CD1F
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Filecoder.ACE
TrendMicro-HouseCallRansom_ExciteRAN.R004C0DLU20
TencentWin32.Trojan.Raas.Auto
IkarusTrojan-Ransom.FileCrypter
FortinetMSIL/Filecoder.6212!tr.ransom
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.Ransom.05f

How to remove Ransom:Win32/ExciteRAN.SL!MTB?

Ransom:Win32/ExciteRAN.SL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment