Ransom

What is “Ransom:Win32/Filecoder.DLK!MTB”?

Malware Removal

The Ransom:Win32/Filecoder.DLK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Filecoder.DLK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Binary file triggered multiple YARA rules

How to determine Ransom:Win32/Filecoder.DLK!MTB?


File Info:

name: 93B141996A4EA07A2FFE.mlw
path: /opt/CAPEv2/storage/binaries/54ed5f812b1f672099e394d33a9c1b73980965a1976972c86bf8a970eff6ec7f
crc32: 38AB07C0
md5: 93b141996a4ea07a2ffead8ee51f1500
sha1: fd3ca6ad5e8310f64e910a0cd52c039693a177bf
sha256: 54ed5f812b1f672099e394d33a9c1b73980965a1976972c86bf8a970eff6ec7f
sha512: a529f6f53357c5d956792c3a9e04289ea7149c1aec249fc028fb911d0f1bfcef0f6a6ac6fe701a8bd4ae638478397d02921e238a257074311e164bcc4321a2cf
ssdeep: 24576:oua8DJSShz305vgNF7/cOCPHPSVs4Eq+QTNX+cfQdS+2MMPishd/Ws5qh03fcaiY:ou+i0aNvoHqs4L95X+cfx/HGCZfji
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9A5F1107690C137D1FE0A7466B1B2304BBCE5212726E7DF5FC829BA5E693C02A75A73
sha3_384: 74aa2c1faad53b0de05af27d17a44929d48de9d4a429272d2a4349f3fffc1f9c2c9ab0e5b6836a26500b2a4c62406c8c
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-04-14 03:04:48

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Builder
FileVersion: 1.0.0.0
InternalName: Builder.exe
LegalCopyright: Copyright © 2016
LegalTrademarks:
OriginalFilename: Builder.exe
ProductName: Builder
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ransom:Win32/Filecoder.DLK!MTB also known as:

LionicTrojan.Win32.GlobeImposter.4!c
AVGWin32:Malware-gen
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
FireEyeGen:Heur.Ransom.REntS.Gen.1
SkyhighArtemis!Trojan
McAfeeArtemis!93B141996A4E
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.Ransom.REntS.Gen.1
SangforRansom.Win32.Filecoder.Vwva
K7AntiVirusTrojan ( 00502c261 )
AlibabaRansom:Win32/GlobeImposter.49b
K7GWTrojan ( 00502c261 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HLTA
APEXMalicious
ClamAVWin.Ransomware.Globeimposter-6991673-1
KasperskyTrojan-PSW.Win32.Stealer.capf
BitDefenderGen:Heur.Ransom.REntS.Gen.1
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10beb9d5
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
F-SecureTrojan.TR/FileCoder.ozghz
ZillyaTrojan.Filecoder.Win32.13621
TrendMicroRansom_Filecoder.R002C0DAA24
SophosTroj/GlobeImp-A
VaristW32/ABRansom.BVML-8643
AviraTR/FileCoder.ozghz
MAXmalware (ai score=88)
Antiy-AVLTrojan[Ransom]/Win32.Globeimposter.gen
MicrosoftRansom:Win32/Filecoder.DLK!MTB
XcitiumMalware@#87hr5zqpdzck
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmTrojan-PSW.Win32.Stealer.capf
GDataGen:Heur.Ransom.REntS.Gen.1
GoogleDetected
BitDefenderThetaGen:NN.ZemsilF.36802.co0@a07w6yp
ALYacMisc.Riskware.RansomBuilder
VBA32TScope.Trojan.MSIL
PandaTrj/RansomGen.A
TrendMicro-HouseCallRansom_Filecoder.R002C0DAA24
RisingRansom.GlobeImposter!1.A538 (CLASSIC)
YandexTrojan.Filecoder!U+SRoNVMkpI
IkarusTrojan-Ransom.GlobeImposter
MaxSecureTrojan.Malware.73593052.susgen
FortinetMSIL/Filecoder.FV!tr.ransom
Cybereasonmalicious.96a4ea
DeepInstinctMALICIOUS

How to remove Ransom:Win32/Filecoder.DLK!MTB?

Ransom:Win32/Filecoder.DLK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment