Ransom

About “Ransom:Win32/Filecoder.AR!MTB” infection

Malware Removal

The Ransom:Win32/Filecoder.AR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Filecoder.AR!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Filecoder.AR!MTB?


File Info:

crc32: D91D09BF
md5: 1d7c2638db04c8ae04722ddde95cf72d
name: 1D7C2638DB04C8AE04722DDDE95CF72D.mlw
sha1: f791ea19c9d0438d3cf5b16dab54cf66ff07db6e
sha256: fa24ce18f8d7727cc1cc6ac7afbff0a0c00ea121fb6619abf3d2da235701a265
sha512: 72be81c53f6dd843466f839bb42ccf46c2f5ce99b0ccf428df73179940287943812a657109e382734daebfdf971798c6359c68808f4f5c2bb8d97c507e50fe4a
ssdeep: 384:TG2eeHZpmlmkSxxFZpV52BXERffKq0JdywUNmGvjMXN1M9NfyXa4Sd4VFFW73hJ:TfZxZl7HAJHUNDAX/2IXa4DFaJDBD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Filecoder.AR!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.306002
FireEyeGeneric.mg.1d7c2638db04c8ae
CAT-QuickHealTrojan.CryptPMF.S16690296
ALYacGen:Variant.Zusy.306002
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005031101 )
BitDefenderGen:Variant.Zusy.306002
K7GWTrojan ( 005031101 )
Cybereasonmalicious.8db04c
CyrenW32/Filecoder.Z.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Zusy-9784403-0
KasperskyHEUR:Trojan-Ransom.Win32.Cryptor.gen
NANO-AntivirusTrojan.Win32.Encoder.gmktnz
RisingRansom.Maoloa!1.C493 (CLASSIC)
Ad-AwareGen:Variant.Zusy.306002
EmsisoftGen:Variant.Zusy.306002 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Encoder.30146
ZillyaTrojan.Filecoder.Win32.11680
TrendMicroRansom.Win32.PURGEN.SMCET
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
SophosML/PE-A
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.Purgen.fw
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan[Ransom]/Win32.GlobeImposter
MicrosoftRansom:Win32/Filecoder.AR!MTB
ArcabitTrojan.Zusy.D4AB52
ZoneAlarmHEUR:Trojan-Ransom.Win32.Cryptor.gen
GDataWin32.Trojan-Ransom.GlobeImposter.O
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R294171
McAfeeGenericRXKC-LN!1D7C2638DB04
VBA32BScope.TrojanRansom.Purgen
MalwarebytesRansom.Maoloa
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.FV
TrendMicro-HouseCallRansom.Win32.PURGEN.SMCET
TencentMalware.Win32.Gencirc.10b705dc
YandexTrojan.GenAsa!9koJnDxCTv4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.73868520.susgen
FortinetW32/Dropper.A!tr
BitDefenderThetaAI:Packer.CC13D81F1F
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM07.1.912B.Malware.Gen

How to remove Ransom:Win32/Filecoder.AR!MTB?

Ransom:Win32/Filecoder.AR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment