Ransom

Ransom:Win32/Maze.SA!MTB removal guide

Malware Removal

The Ransom:Win32/Maze.SA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Maze.SA!MTB virus can do?

  • Anomalous binary characteristics

How to determine Ransom:Win32/Maze.SA!MTB?


File Info:

crc32: 79E6B7FA
md5: 97d4e0f40b49aa014400d8027cedd99b
name: 97D4E0F40B49AA014400D8027CEDD99B.mlw
sha1: be208854387db2e02e81dc00bb244f3c0d1bc98f
sha256: 0165be8e503ee202c67388e4b16c2f1f137e715100c83a89bc86c06f3a94073b
sha512: 56bd92120a1f625a1c825432d58d1025db41f0d4b883f01f74bd049872e94e5d2df5dc6769880e0426702ab0efad93060f5f60d8ce0ffcd92e26f5c96fbc645f
ssdeep: 12288:NrVN7SUmCePrBeyZ1doI0QQk1C1XmNr78QPzIdbT+o:9eFBFdoIok1Sc8+o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2024
InternalName: Fuck south korea
FileVersion: 1.0.0.1
CompanyName: Kim Jong Un
ProductName: We love our Emperor, Kim Jong Un!
ProductVersion: 1.0.0.1
FileDescription: Coded by Gruja
OriginalFilename: kim.exe
Translation: 0x0412 0x04b0

Ransom:Win32/Maze.SA!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005651661 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.30958
CynetMalicious (score: 100)
ALYacTrojan.Ransom.ChaCha
CylanceUnsafe
ZillyaTrojan.Cryptor.Win32.460
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Instructions.ec0d6c2a
K7GWTrojan ( 005651661 )
Cybereasonmalicious.40b49a
SymantecTrojan Horse
ESET-NOD32a variant of Win32/GenKryptik.EDCX
ZonerTrojan.Win32.92222
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Maze-7473772-0
KasperskyTrojan-Ransom.Win32.Maze.fb
BitDefenderGen:Variant.Jaik.39009
NANO-AntivirusTrojan.Win32.Encoder.gyymoj
MicroWorld-eScanGen:Variant.Jaik.39009
TencentWin32.Trojan.Instructions.Hwcq
Ad-AwareGen:Variant.Jaik.39009
SophosMal/Generic-R + Mal/Ransom-FZ
ComodoMalware@#2jydh76b38k33
BitDefenderThetaGen:NN.ZexaF.34608.6C0@ausERCdi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.MAZE.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.97d4e0f40b49aa01
EmsisoftGen:Variant.Jaik.39009 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Cryptor.os
WebrootW32.Ransom.Maze
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Maze.SA!MTB
ArcabitTrojan.Jaik.D9861
AegisLabTrojan.Win32.Instructions.j!c
ZoneAlarmTrojan-Ransom.Win32.Maze.fb
GDataGen:Variant.Jaik.39009
AhnLab-V3Trojan/Win32.RansomCrypt.C4249431
Acronissuspicious
McAfeeGenericRXKD-FN!97D4E0F40B49
MAXmalware (ai score=100)
VBA32BScope.Trojan.Wacatac
MalwarebytesRansom.Maze
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.MAZE.SM
RisingRansom.Instructions!8.1028A (CLOUD)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.89894287.susgen
FortinetW32/Kryptik.HAFZ!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.c75

How to remove Ransom:Win32/Maze.SA!MTB?

Ransom:Win32/Maze.SA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment