Ransom

How to remove “Ransom:Win32/FileCrypter.MK!MTB”?

Malware Removal

The Ransom:Win32/FileCrypter.MK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/FileCrypter.MK!MTB virus can do?

  • Writes a potential ransom message to disk
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/FileCrypter.MK!MTB?


File Info:

crc32: 0C07A203
md5: a0eaea3e3f950d5623783802509073e4
name: A0EAEA3E3F950D5623783802509073E4.mlw
sha1: 7cfe841cb41af0597974a9e1b46ed073c880aaf1
sha256: 7eb179cdd0238c248d1c834b450ed74f5d1a6d60e2cec006bf6edd222190b1d9
sha512: cd0a57838937ba81746f5c96b029a113e3529c3b702e2d6b9d23beea010a84ad246954bdeede16f47b7ef0195a1e4662f2a66634616e265d41d72c1eed75889a
ssdeep: 3072:MbOTRwYckApvw14pcODvX/kyeAYcWNzs2C3Zm4YSYoj1ZYJJCpdXfabI8pJKgcJz:IOsZiKRJWWY1dJJQdHcYuF+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/FileCrypter.MK!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.CryLock.23B05084
FireEyeGeneric.mg.a0eaea3e3f950d56
CAT-QuickHealTrojanRansom.Cryakl
ALYacTrojan.Ransom.Cryakl
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004c1e461 )
BitDefenderGeneric.Ransom.CryLock.23B05084
K7GWTrojan ( 004c1e461 )
Cybereasonmalicious.e3f950
BitDefenderThetaAI:Packer.DD13F7A521
CyrenW32/Dropper.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.EQ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Ransomware.Cryakl-9797483-0
KasperskyHEUR:Trojan-Ransom.Win32.Cryakl.gen
AlibabaRansom:Win32/FileCrypter.0c66c916
NANO-AntivirusTrojan.Win32.Cryakl.hofalo
Ad-AwareGeneric.Ransom.CryLock.23B05084
SophosMal/Generic-S
ComodoMalware@#2ms9jdfuqxuat
F-SecureHeuristic.HEUR/AGEN.1134200
DrWebTrojan.Encoder.32161
ZillyaTrojan.Filecoder.Win32.15239
TrendMicroRansom.Win32.BUHTRAP.SM
McAfee-GW-EditionBehavesLike.Win32.Wanex.dh
EmsisoftGeneric.Ransom.CryLock.23B05084 (B)
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.Generic.fsshu
AviraHEUR/AGEN.1134200
MAXmalware (ai score=81)
Antiy-AVLTrojan[Ransom]/Win32.Cryakl
MicrosoftRansom:Win32/FileCrypter.MK!MTB
ArcabitGeneric.Ransom.CryLock.23B05084
AhnLab-V3Malware/Win32.Ransom.C4179653
ZoneAlarmHEUR:Trojan-Ransom.Win32.Cryakl.gen
GDataGeneric.Ransom.CryLock.23B05084
CynetMalicious (score: 100)
McAfeeRansom-Crylock!A0EAEA3E3F95
VBA32BScope.Trojan.Agent
MalwarebytesRansom.CryLocker
PandaTrj/CI.A
TrendMicro-HouseCallRansom.Win32.BUHTRAP.SM
RisingRansom.BlackRabbit!1.D199 (CLOUD)
YandexTrojan.Filecoder!/CkrtTgc9ok
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.EQ!tr.ransom
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Ransom.Criakl.HwUBA1UA

How to remove Ransom:Win32/FileCrypter.MK!MTB?

Ransom:Win32/FileCrypter.MK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment