Ransom

Ransom:Win32/Maui.A removal tips

Malware Removal

The Ransom:Win32/Maui.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Maui.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Possible date expiration check, exits too soon after checking local time
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom:Win32/Maui.A?


File Info:

name: 2D02F5499D35A8DFFB4C.mlw
path: /opt/CAPEv2/storage/binaries/830207029d83fd46a4a89cd623103ba2321b866428aa04360376e6a390063570
crc32: DA663FC7
md5: 2d02f5499d35a8dffb4c8bc0b7fec5c2
sha1: 870ccd59ad2d3808c014c7c1dcc8a54de375db0c
sha256: 830207029d83fd46a4a89cd623103ba2321b866428aa04360376e6a390063570
sha512: a498ae7e85f3aed239b6e7c27ab9f4dd352973706cfbe07d821f7bfae39a5637b3a15acd45e272c669e9674f6ae4fb3a18dcf9276816f376e1fb32ec17d68791
ssdeep: 12288:4+2NRE6xDWPOO3Kt7RJatTrAtfpYqCXd9rxhQjxn:4hRxWPOO3Kt7FfpYhXjHQjxn
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C3F49E06B6C2D4B3D8A6417A11B3937B4E37FE22432AD6C3879129258D753E16E3E3C5
sha3_384: db05e8a2ec0fde63b01a8799fd6690e74a2d8da9f5731c88c3e74db31ac950e13044d3a72aeb070c822063abf314016f
ep_bytes: e843930000e9a5feffff8bff558bec83
timestamp: 2021-04-24 05:20:04

Version Info:

0: [No Data]

Ransom:Win32/Maui.A also known as:

LionicTrojan.Win32.Zusy.4!c
ElasticWindows.Ransomware.Maui
DrWebTrojan.Encoder.35555
MicroWorld-eScanGen:Variant.Zusy.422033
CAT-QuickHealRansom.Maui.S28391866
McAfeeRDN/Zusy
CylanceUnsafe
VIPREGen:Variant.Zusy.422033
K7AntiVirusTrojan ( 005954981 )
BitDefenderGen:Variant.Zusy.422033
K7GWTrojan ( 005954981 )
ArcabitTrojan.Zusy.D67091
CyrenW32/Ransom.KCMG-6809
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Filecoder.OLU
TrendMicro-HouseCallRansom.Win32.MAUICRYPT.YACGG
Paloaltogeneric.ml
ClamAVWin.Ransomware.Maui-9956167-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
NANO-AntivirusTrojan.Win32.FileCoder.jpxgge
ViRobotTrojan.Win32.S.Ransom.781998
RisingRansom.Maui!1.DEFB (CLASSIC)
Ad-AwareGen:Variant.Zusy.422033
SophosTroj/Maui-A
ZillyaTrojan.Filecoder.Win32.24813
TrendMicroRansom.Win32.MAUICRYPT.YACGG
McAfee-GW-EditionRDN/Zusy
FireEyeGen:Variant.Zusy.422033
JiangminTrojan.Agent.eamj
WebrootW32.Ransom.Maui
AviraTR/FileCoder.nbrdy
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.330C
KingsoftWin32.Troj.Generic.jm.(kcloud)
MicrosoftRansom:Win32/Maui.A
GDataGen:Variant.Zusy.422033
AhnLab-V3Ransomware/Win.MAUICRYPT.C5197495
ALYacTrojan.Ransom.MauiCrypt
VBA32TrojanRansom.Maui
MalwarebytesRansom.Maui
PandaTrj/RansomGen.A
APEXMalicious
TencentMalware.Win32.Gencirc.11fdfc80
IkarusTrojan-Ransom.Maui
MaxSecureTrojan.Malware.12310942.susgen
FortinetW32/Agent.C5C2!tr
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/Maui.A?

Ransom:Win32/Maui.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment