Ransom

Ransom:Win32/MedusaLocker.B!MTB removal guide

Malware Removal

The Ransom:Win32/MedusaLocker.B!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/MedusaLocker.B!MTB virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the MedusaLocker malware family
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to masquerade or mimic a legitimate process or file name
  • Attempts to modify UAC prompt behavior
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/MedusaLocker.B!MTB?


File Info:

name: 792C63E062E97BDBA54F.mlw
path: /opt/CAPEv2/storage/binaries/5e0587e61d94a40091480a2f5f78621362265b8702b3558a0db536693159865f
crc32: 99931A77
md5: 792c63e062e97bdba54ffb95636b38d9
sha1: ba3e10ce06ea67224ae577eab44f17d16e08e22b
sha256: 5e0587e61d94a40091480a2f5f78621362265b8702b3558a0db536693159865f
sha512: 1f2378036c4031f05248b56a032063093daf02910bde5ac4ef2d546bc5fdaf4f5cb465a8a8c3286410642275ae7d45803dd1d53d533f770e26037072e2a03735
ssdeep: 24576:mVUtCZxVgDxcIKHcN2xcdbp+OJulrrXpobWMNhG/VO3Q0hN9jfWKXN:mmt0/6xKHmdYflrrXpovn3Q0hN9D
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E8C53911BB518129FEF301F78EFD649D142DBAD00B9894C7A18C56EE866ABE13D32353
sha3_384: 37102341de8aa0e03f12ff67c5c08f06554eeab24922c819947ecfdd2eba133aa3aa921cbac1d76c4439b5a96d3b826f
ep_bytes: e9d1ca0c00e90cc01000e9d70a0400e9
timestamp: 2019-11-18 18:09:18

Version Info:

0: [No Data]

Ransom:Win32/MedusaLocker.B!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Imps.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.MedusaLocker.3B192263
CAT-QuickHealRansom.Medusa.S13913779
McAfeeRansomware-GUB!792C63E062E9
MalwarebytesRansom.Medusa
ZillyaTrojan.Filecoder.Win32.11349
SangforRansom.Win32.MedusaLocker.B!MTB
K7AntiVirusTrojan ( 0055a9531 )
AlibabaTrojan:Win32/MedusaLocker.eb9a8b80
K7GWTrojan ( 0055a9531 )
Cybereasonmalicious.062e97
SymantecRansom.Cryptolocker
ESET-NOD32a variant of Win32/Filecoder.MedusaLocker.C
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.MedusaLocker-9811279-1
KasperskyTrojan.Win32.DelShad.bqv
BitDefenderGeneric.Ransom.MedusaLocker.3B192263
NANO-AntivirusTrojan.Win32.Encoder.gkbmcm
AvastWin32:Trojan-gen
TencentWin32.Trojan.Filecoder.Jajl
Ad-AwareGeneric.Ransom.MedusaLocker.3B192263
SophosMal/Ransom-FX
ComodoMalware@#2wcjb5x5pfaz1
F-SecureHeuristic.HEUR/AGEN.1237934
DrWebTrojan.Encoder.30199
VIPREGeneric.Ransom.MedusaLocker.3B192263
TrendMicroRansom.Win32.MEDUSALOCKER.SMTH
McAfee-GW-EditionRansomware-GUB!792C63E062E9
FireEyeGeneric.mg.792c63e062e97bdb
EmsisoftGeneric.Ransom.MedusaLocker.3B192263 (B)
IkarusTrojan-Ransom.Medusalocker
JiangminTrojan.DelShad.kx
WebrootW32.Malware.Gen
GoogleDetected
AviraHEUR/AGEN.1237934
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.6769
MicrosoftRansom:Win32/MedusaLocker.B!MTB
ArcabitGeneric.Ransom.MedusaLocker.3B192263
GDataGeneric.Ransom.MedusaLocker.3B192263
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R335910
BitDefenderThetaGen:NN.ZexaF.34754.LQW@aWB0stki
ALYacTrojan.Ransom.MedusaLocker
VBA32Trojan.DelShad
CylanceUnsafe
TrendMicro-HouseCallRansom.Win32.MEDUSALOCKER.SMTH
RisingRansom.MedusaLocker!1.BE63 (CLASSIC)
YandexTrojan.DelShad!o6NEdaVW3Yw
MaxSecureTrojan.Malware.74712911.susgen
FortinetW32/MedusaLocker.C!tr.ransom
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/MedusaLocker.B!MTB?

Ransom:Win32/MedusaLocker.B!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment