Ransom

How to remove “Ransom:Win32/Hydra.PAC!MTB”?

Malware Removal

The Ransom:Win32/Hydra.PAC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Hydra.PAC!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Starts servers listening on 127.0.0.1:0
  • Uses Windows utilities for basic functionality
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.telegram.org

How to determine Ransom:Win32/Hydra.PAC!MTB?


File Info:

crc32: A66DBAB2
md5: 25e8552436afeba089f1a0a5a1dc4767
name: 25E8552436AFEBA089F1A0A5A1DC4767.mlw
sha1: 33805b7ef4f54d3ff5f7b92751a54586ca5d4a49
sha256: 14c224c702b14792e13eb89862a06a06c583ad3d9de31860c32c12ce2c733c59
sha512: 50c92a2623828faa55c4b5eb3d1f615ba6ebc0e2217ffca424dd650d2693780edb3b61e1da7e9b406d593b65d7f978fda768200a588fc5b55c2fbafcb3657879
ssdeep: 24576:l1p+JolsHzvS9CH+lG1QGogCjsC4kMNpeuRx6yRA1vwaMNKsaRQ/b4OXox97:9s9HzvS9CH+lG1QG8BK0KaIaRCs97
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Hydra.PAC!MTB also known as:

Elasticmalicious (high confidence)
ALYacGen:Variant.Ransom.Hydra.1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OIH
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.DMR.gen
BitDefenderGen:Variant.Ransom.Hydra.1
MicroWorld-eScanGen:Variant.Ransom.Hydra.1
Ad-AwareGen:Variant.Ransom.Hydra.1
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.!CW@a0ZnnYhi
McAfee-GW-EditionGenericRXPW-UA!25E8552436AF
FireEyeGen:Variant.Ransom.Hydra.1
EmsisoftGen:Variant.Ransom.Hydra.1 (B)
JiangminTrojan.DMR.e
AviraTR/Redcap.iahid
MicrosoftRansom:Win32/Hydra.PAC!MTB
ArcabitTrojan.Ransom.Hydra.1
GDataGen:Variant.Ransom.Hydra.1
TACHYONRansom/W32.Ouroboros.1016832
McAfeeGenericRXPW-UA!25E8552436AF
MAXmalware (ai score=83)
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
IkarusTrojan-Ransom.Medusalocker
FortinetW32/Filecoder.OIH!tr.ransom
AVGWin32:MalwareX-gen [Trj]

How to remove Ransom:Win32/Hydra.PAC!MTB?

Ransom:Win32/Hydra.PAC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment