Ransom

Ransom:Win32/Nemty.PF!MTB removal instruction

Malware Removal

The Ransom:Win32/Nemty.PF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Nemty.PF!MTB virus can do?

  • Unconventionial language used in binary resources: Latvian
  • Anomalous binary characteristics

How to determine Ransom:Win32/Nemty.PF!MTB?


File Info:

crc32: 49C2D745
md5: b23730691782b62923a590da09fd7d65
name: B23730691782B62923A590DA09FD7D65.mlw
sha1: c010d77769fa471fb9a4ca247809ed2b12bb17a4
sha256: 3d852ca618763ced2e280f0c0079e804935b70dcd4adc3912c2e2b3965e196c4
sha512: a16cd54343839663f892f69e29882ef4d38793620ddceb68cae6d06a2e9e8afc98a1af465f74c248fffd349273fca4fd8b248230520a6d7e1d683143669aec50
ssdeep: 6144:lFEEvGd7Gv10H/4BUqOkcqq5uEsjlSk1Ru:lFEEvEkqwTOR3sDjlSk1Ru
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Nemty.PF!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00558c3a1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.29417
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Nemty
CylanceUnsafe
ZillyaTrojan.Zenpak.Win32.1281
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Nemty.f8dee556
K7GWTrojan ( 00558c3a1 )
Cybereasonmalicious.91782b
CyrenW32/Kryptik.AHO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GWVK
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan.Win32.Zenpak.lcs
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Zenpak.gbxyuv
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Zenpak.Pcih
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-R + Mal/GandCrab-G
F-SecureHeuristic.HEUR/AGEN.1106378
BitDefenderThetaGen:NN.ZexaF.34670.tyW@amT7x8jc
TrendMicroRansom.Win32.NEMTY.THJAEAI
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.b23730691782b629
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Zenpak.ach
AviraHEUR/AGEN.1106378
Antiy-AVLTrojan/Win32.Zenpak
MicrosoftRansom:Win32/Nemty.PF!MTB
ArcabitTrojan.Brsecmon.1
ZoneAlarmTrojan.Win32.Zenpak.lcs
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win32.MalPe.R293164
Acronissuspicious
McAfeeRDN/Ransom.hi
MAXmalware (ai score=85)
VBA32BScope.Backdoor.Tofsee
MalwarebytesSpyware.RaccoonStealer.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.NEMTY.THJAEAI
RisingTrojan.Kryptik!1.BDD3 (CLOUD)
YandexTrojan.Zenpak!3APF4Ofr9r0
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GZXE!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Nemty.HwoC2B8B

How to remove Ransom:Win32/Nemty.PF!MTB?

Ransom:Win32/Nemty.PF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment