Ransom

Ransom:Win32/lockbit.DB!MTB removal guide

Malware Removal

The Ransom:Win32/lockbit.DB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/lockbit.DB!MTB virus can do?

  • A process attempted to delay the analysis task.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Clears Windows events or logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/lockbit.DB!MTB?


File Info:

crc32: D175C35D
md5: fb5185d4040920815dd8c79ca0b74bf2
name: FB5185D4040920815DD8C79CA0B74BF2.mlw
sha1: 51117fd896b999867465d96aeedbfc3b901cd035
sha256: 5e5c70bed6fdee8a697d132800aec39825f6382403f79da1d70dc9580fce1999
sha512: daeab313d44bc90be807df23b412445d4ab4f7662cc98b1c411b9b199728826a49abb7edda828cc2864dabde0a63129991cc95295bbeb049fdd0973d96bb71f9
ssdeep: 3072:ym0ROZIL87L1yoklfzGp3XjRaDyZYMqqD/A+lHlC:ypMCL8rpHjRa0qqD/NjC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/lockbit.DB!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055895f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericRI.S17164109
ALYacGeneric.Ransom.LockBit.5886A564
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.14444
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0055895f1 )
Cybereasonmalicious.404092
CyrenW32/LockBit.A.gen!Eldorado
SymantecRansom.Lockbit
ESET-NOD32a variant of Win32/Filecoder.Lockbit.B
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.LockBitCombined-9375766-1
KasperskyHEUR:Trojan-Ransom.Win32.Lockbit.vho
BitDefenderGeneric.Ransom.LockBit.5886A564
NANO-AntivirusTrojan.Win32.Filecoder.hkawtb
MicroWorld-eScanGeneric.Ransom.LockBit.5886A564
Ad-AwareGeneric.Ransom.LockBit.5886A564
SophosML/PE-A
BitDefenderThetaAI:Packer.4C70C98020
TrendMicroRansom.Win32.LOCKBIT.SMDS
McAfee-GW-EditionBehavesLike.Win32.Backdoor.ch
FireEyeGeneric.mg.fb5185d404092081
EmsisoftGeneric.Ransom.LockBit.5886A564 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.DelShad.wr
AviraTR/Crypt.XPACK.Gen7
eGambitUnsafe.AI_Score_62%
Antiy-AVLTrojan/Generic.ASMalwS.3068D02
MicrosoftRansom:Win32/lockbit.DB!MTB
ArcabitGeneric.Ransom.LockBit.5886A564
GDataGeneric.Ransom.LockBit.5886A564
AhnLab-V3Malware/Win32.Generic.C3889680
Acronissuspicious
McAfeeRansom-Lkbit!FB5185D40409
MAXmalware (ai score=83)
VBA32BScope.Trojan.DelShad
MalwarebytesRansom.LockBit
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.LOCKBIT.SMDS
RisingRansom.LockBit!1.C39F (RDMK:cmRtazq5dpHmdi+W2qwRsBz2CnC/)
YandexTrojan.DelShad!VkgnVY2FtqM
FortinetW32/Filecoder.NXQ!tr.ransom
AVGWin32:RansomX-gen [Ransom]

How to remove Ransom:Win32/lockbit.DB!MTB?

Ransom:Win32/lockbit.DB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment