Ransom

About “Ransom:Win32/LockCrypt.MAK!MTB” infection

Malware Removal

The Ransom:Win32/LockCrypt.MAK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/LockCrypt.MAK!MTB virus can do?

  • Authenticode signature is invalid

How to determine Ransom:Win32/LockCrypt.MAK!MTB?


File Info:

name: 3F6419DFEA6DF328600A.mlw
path: /opt/CAPEv2/storage/binaries/8598d7be8dd6f7f5b0b482c3fe5b8f6fb5f191f45dcae9262c7386e962a0663a
crc32: 7C48F5D3
md5: 3f6419dfea6df328600a173be69b2d02
sha1: 98c41ac2c8642e4652bab04855b4f11a6762712e
sha256: 8598d7be8dd6f7f5b0b482c3fe5b8f6fb5f191f45dcae9262c7386e962a0663a
sha512: ffc8fb93d0121e9ba1f7b83009d30e73f602acfbc944122c4db36bc79af54611ea7d70ea176d22e35cd8f2b462422997ce49ac0d46ce931da2672919e97d873e
ssdeep: 384:x3geKmNmbeMEaWI6SLrmn2ZQGlRYPDcYXf:2yw6nV1SLqncQEg/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6520716AEE58273E3F1EAB265798602DE3EB1AA9437C30EDF884D001636510DF74D5E
sha3_384: 0b82c3ea4f59cc6d6b05212cea8183e6400f46b60db4feb8e211eca1151457462ae64681dd7122056edbc24befe1949a
ep_bytes: 558bec83c4fc6a01e8d90400006a00e8
timestamp: 2018-02-18 06:02:45

Version Info:

0: [No Data]

Ransom:Win32/LockCrypt.MAK!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.12135
CynetMalicious (score: 100)
FireEyeGeneric.mg.3f6419dfea6df328
ALYacGeneric.Ransom.LockCrypt.BA282416
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.wsc (mx-v)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/AntiAV.1f7e5acc
K7GWTrojan ( 005451b81 )
K7AntiVirusTrojan ( 005451b81 )
BitDefenderThetaAI:Packer.7AE4498E1F
CyrenW32/Threat-HLLSI-based!Maximus
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NPA
TrendMicro-HouseCallRansom_LOCKCRYPT.E
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.AntiAV
BitDefenderGeneric.Ransom.LockCrypt.BA282416
SUPERAntiSpywareRansom.Filecoder/Variant
MicroWorld-eScanGeneric.Ransom.LockCrypt.BA282416
TencentWin32.Trojan.Raas.Auto
EmsisoftGeneric.Ransom.LockCrypt.BA282416 (B)
ComodoMalware@#1qloe1a85dhd7
ZillyaTrojan.AntiAV.Win32.10785
TrendMicroRansom_LOCKCRYPT.E
McAfee-GW-EditionTrojan-FOQP!3F6419DFEA6D
SophosMal/Generic-R + Mal/Ransom-FO
Paloaltogeneric.ml
JiangminTrojan.AntiAV.apd
AviraTR/FileCoder.xlntk
Antiy-AVLTrojan/Generic.ASMalwS.251FCD2
GridinsoftRansom.Win32.Generic.sa
MicrosoftRansom:Win32/LockCrypt.MAK!MTB
ViRobotTrojan.Win32.Z.Antiav.13824
GDataWin32.Trojan-Ransom.Filecoder.CG@gen
AhnLab-V3Malware/Win32.Generic.C2436577
VBA32BScope.Trojan.AntiAV
MAXmalware (ai score=99)
MalwarebytesMalware.AI.2732870930
APEXMalicious
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.GenAsa!Zfq2Wvbcf0w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.425.susgen
FortinetW32/Ransom.FO!tr.ransom
AVGFileRepMalware
Cybereasonmalicious.fea6df
PandaTrj/GdSda.A

How to remove Ransom:Win32/LockCrypt.MAK!MTB?

Ransom:Win32/LockCrypt.MAK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment