Ransom

Ransom:Win32/FileCryptor.I!MTB removal

Malware Removal

The Ransom:Win32/FileCryptor.I!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/FileCryptor.I!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/FileCryptor.I!MTB?


File Info:

crc32: 3DD6341C
md5: f6555f32cab7207526423404f8e5d7ab
name: F6555F32CAB7207526423404F8E5D7AB.mlw
sha1: 13ba64e623be18d7ec452343b6f5dcd251b60fd2
sha256: 34cfdbcd76f27b2e96373bb154878dfae0fa05efe58d180c7596371b447d1244
sha512: 6130556e844273a6f3d164c171e98d2359e2d062e13d706022e42e8e9263d5d9fd3f663777889688b34f7a9b88a3d72c0aff9da2ea33560faf36e3e2451e2ad7
ssdeep: 768:xLtBwIitUg95twwTDtusZ9UCcZuQ0nqN4gqyImJLX4kp:dt9SxrthPtusBcZuQGDByB5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Wwn.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Wwn.exe

Ransom:Win32/FileCryptor.I!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.32062
MicroWorld-eScanTrojan.GenericKD.43396568
McAfeeArtemis!F6555F32CAB7
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.1616
AegisLabTrojan.MSIL.Encoder.j!c
SangforMalware
K7AntiVirusTrojan ( 005699c61 )
BitDefenderTrojan.GenericKD.43396568
K7GWTrojan ( 005699c61 )
Cybereasonmalicious.623be1
ArcabitTrojan.Generic.D2962DD8
InvinceaMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34634.cm0@aOELcIn
CyrenW32/Ransom.HVBP-2422
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.MSIL.Encoder.gen
AlibabaRansom:Win32/FileCryptor.29ac2f39
NANO-AntivirusTrojan.Win32.Ransom.hmzyfc
Ad-AwareTrojan.GenericKD.43396568
EmsisoftTrojan.GenericKD.43396568 (B)
ComodoMalware@#2oggayarlqyrf
F-SecureTrojan.TR/Ransom.hvbsa
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
FireEyeGeneric.mg.f6555f32cab72075
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.ppwp
AviraTR/Ransom.hvbsa
Antiy-AVLTrojan[Ransom]/MSIL.Encoder
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/FileCryptor.I!MTB
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Encoder.gen
GDataTrojan.GenericKD.43396568
CynetMalicious (score: 100)
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.43396568
MAXmalware (ai score=85)
MalwarebytesRansom.WannaCrypt
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of MSIL/Filecoder.AAQ
TencentMsil.Trojan.Encoder.Ecjt
YandexTrojan.Filecoder!yI6Oc/To16M
IkarusTrojan-PSW.Fareit
FortinetMSIL/Filecoder.WH!tr
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.Ransom.d23

How to remove Ransom:Win32/FileCryptor.I!MTB?

Ransom:Win32/FileCryptor.I!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment