Ransom

How to remove “Ransom:Win32/FonixCrypt.MA!MTB”?

Malware Removal

The Ransom:Win32/FonixCrypt.MA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/FonixCrypt.MA!MTB virus can do?

  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

edgedl.me.gvt1.com
update.googleapis.com
redirector.gvt1.com
r2—sn-bpb5oxu-3c2k.gvt1.com

How to determine Ransom:Win32/FonixCrypt.MA!MTB?


File Info:

crc32: C81EF90B
md5: 25e6e8d32e96e73ea0eb72a31d5016db
name: 25E6E8D32E96E73EA0EB72A31D5016DB.mlw
sha1: 67dd47851020532a391400e1fe6d2d6a6881ee3c
sha256: 80823ab41a9fba58223b733b83b4d52968aed384623694f4d2743288b4659624
sha512: a91c7f991afedaa7af7591eed801b81665a7d0190f4617ee373a96ca3ce7c85ccb5ea1f8d0217507e61b58d822ab2384feb7d41fb28c9335ca9d86afad115cf7
ssdeep: 6144:jNsrj6U6kgnydIwFoKwJqZ1y1rufjyl6es1vK+cISzW0OyBHTP5ZE:jurj6U+yywWKw0XyUmlds1vKdzW0OGT
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/FonixCrypt.MA!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f76a01 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericRI.S16503372
ALYacGeneric.Ransom.DMR.67624C68
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWTrojan ( 004f76a01 )
Cybereasonmalicious.32e96e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FONIX.A
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Fonix-9811540-0
KasperskyVHO:Trojan-Ransom.Win32.Agent.gen
BitDefenderGeneric.Ransom.DMR.67624C68
NANO-AntivirusTrojan.Win32.Encoder.iamrhz
MicroWorld-eScanGeneric.Ransom.DMR.67624C68
Ad-AwareGeneric.Ransom.DMR.67624C68
SophosMal/Generic-S
ComodoMalware@#24xjleyfrzfqr
F-SecureTrojan.TR/FileCoder.hpqpr
BitDefenderThetaGen:NN.ZexaF.34692.vmGfa4Jeucbi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.FONIX.SMTH
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.25e6e8d32e96e73e
EmsisoftGeneric.Ransom.DMR.67624C68 (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.StartSurf.cmvv
AviraTR/FileCoder.hpqpr
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/FonixCrypt.MA!MTB
ArcabitGeneric.Ransom.DMR.67624C68
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.Ransom.DMR.67624C68
TACHYONRansom/W32.Fonix.912384
AhnLab-V3Malware/Win.Ransom.R418630
Acronissuspicious
McAfeeGenericRXAA-AA!25E6E8D32E96
MAXmalware (ai score=81)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.Fonix
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.FONIX.SMTH
RisingTrojan.Filecoder!8.68 (TFE:dGZlOgWS6gfH/AgCVg)
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Generic.NHQ!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove Ransom:Win32/FonixCrypt.MA!MTB?

Ransom:Win32/FonixCrypt.MA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment