Ransom

Should I remove “Ransom:Win32/LockBit.PA!MTB”?

Malware Removal

The Ransom:Win32/LockBit.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/LockBit.PA!MTB virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (508 unique times)
  • A named pipe was used for inter-process communication
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/LockBit.PA!MTB?


File Info:

crc32: 69489444
md5: c0cacc5bf97b854b6025fe0973dc076f
name: C0CACC5BF97B854B6025FE0973DC076F.mlw
sha1: 0cc92cccebed351b1b5e6b28082af5e00da28678
sha256: 15a7d528587ffc860f038bb5be5e90b79060fbba5948766d9f8aa46381ccde8a
sha512: a4183aee5236e02177e4fd2fbd8368a857415f6687194403178d1c5ad9b21a551ec82dd9e406d57cf164eff43e797da095ccda7970934c96037dd82649424cc6
ssdeep: 1536:uX2+0E0agIvDTJACKtr7rjgSvofcsVaIplFI:c0l1qxY7rjV/sVLDFI
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/LockBit.PA!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Ransomware.LockBitCombined-9375766-1
Qihoo-360Win32/Ransom.LockBit.HwsBIMsA
McAfeeArtemis!C0CACC5BF97B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.DelShad.trhq
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055895f1 )
BitDefenderGeneric.Ransom.LockBit.82A7AF3B
K7GWTrojan ( 0055895f1 )
Cybereasonmalicious.bf97b8
ArcabitGeneric.Ransom.LockBit.82A7AF3B
CyrenW32/Filecoder.AD.gen!Eldorado
SymantecRansom.Wannacry
ESET-NOD32a variant of Win32/Filecoder.Lockbit.B
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.DelShad.ckt
AlibabaRansom:Win32/generic.ali2000010
NANO-AntivirusTrojan.Win32.Filecoder.gxkpfk
MicroWorld-eScanGeneric.Ransom.LockBit.82A7AF3B
TencentWin32.Trojan.Delshad.Sxxy
Ad-AwareGeneric.Ransom.LockBit.82A7AF3B
EmsisoftGeneric.Ransom.LockBit.82A7AF3B (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Encoder.30932
ZillyaTrojan.DelShad.Win32.378
TrendMicroRansom.Win32.LOCKBIT.SMDS
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.c0cacc5bf97b854b
SophosMal/Generic-R + Troj/Locky-ACO
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.DelShad.rn
WebrootW32.DelShad
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.DelShad
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/LockBit.PA!MTB
ViRobotTrojan.Win32.S.LockBit.54272
ZoneAlarmTrojan.Win32.DelShad.ckt
GDataWin32.Trojan-Ransom.Lockibit.A
AhnLab-V3Malware/Win32.Generic.C3986963
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.dmGfauBdORn
ALYacTrojan.Ransom.Filecoder
TACHYONRansom/W32.LockBit.103936
VBA32BScope.Trojan.DelShad
MalwarebytesRansom.LockBit
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.LOCKBIT.SMDS
RisingRansom.Agent!8.6B7 (CLOUD)
YandexTrojan.DelShad!qCPIRKxlc54
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Filecoder.NXQ!tr.ransom
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.12024959.susgen

How to remove Ransom:Win32/LockBit.PA!MTB?

Ransom:Win32/LockBit.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment