Ransom Worm

Ransom:Win32/JSWorm.A!MTB information

Malware Removal

The Ransom:Win32/JSWorm.A!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/JSWorm.A!MTB virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/JSWorm.A!MTB?


File Info:

crc32: 866D9AF1
md5: 74701302d6cb1e2f3874817ac499b84a
name: 74701302D6CB1E2F3874817AC499B84A.mlw
sha1: f48e7aa74b48dbaceacb359b67ba88e6fc32178e
sha256: 1b871a34c25dd253b563a5c52d054a9dd79f462e047908b6e8f523ff0732ab97
sha512: cc10f792abbaa0c4c57ca5429024ab077cb11d06f8dc9a63a2f55fae2e1b95fb046f575a99f0862187c6915d0cd13c9e77ba636453379a0f3f01a2a7b20c6fb1
ssdeep: 1536:ouYz97+olAPutkm8PNJjCWoVFHirk+VWi+4w:ou60h9PNJjGRi+4w
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/JSWorm.A!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005588651 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.28931
CynetMalicious (score: 100)
ALYacTrojan.Ransom.JSWorm
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 005588651 )
Cybereasonmalicious.2d6cb1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.JSWorm.F
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.JSWORM.B4880BE9
NANO-AntivirusTrojan.Win32.Filecoder.ftapjv
MicroWorld-eScanDeepScan:Generic.Ransom.JSWORM.B4880BE9
TencentWin32.Trojan.Raas.Auto
Ad-AwareDeepScan:Generic.Ransom.JSWORM.B4880BE9
SophosMal/Generic-S
BitDefenderThetaAI:Packer.9F4EFE6A1D
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.JSWORM.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
FireEyeGeneric.mg.74701302d6cb1e2f
EmsisoftDeepScan:Generic.Ransom.JSWORM.B4880BE9 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/FileCoder.wnyrh
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2C040CB
MicrosoftRansom:Win32/JSWorm.A!MTB
AegisLabTrojan.Win32.Generic.4!c
GDataDeepScan:Generic.Ransom.JSWORM.B4880BE9
AhnLab-V3Malware/Win32.Generic.C3329702
McAfeeRDN/Ransom
MAXmalware (ai score=100)
VBA32BScope.Trojan.Agent
MalwarebytesRansom.JSWorm
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.JSWORM.SMA
RisingRansom.JSWorm!8.1112F (CLOUD)
YandexTrojan.GenAsa!s14KFfnMH0s
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Filecoder.NVV!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/JSWorm.A!MTB?

Ransom:Win32/JSWorm.A!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment