Ransom

Ransom:Win32/NetWalker.MLS!MTB information

Malware Removal

The Ransom:Win32/NetWalker.MLS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/NetWalker.MLS!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Saudi Arabia)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ocsp.digicert.com
www.msftconnecttest.com
api.myip.com

How to determine Ransom:Win32/NetWalker.MLS!MTB?


File Info:

crc32: 2F894847
md5: ccede1200a6e8eff54a358fa1e6d119a
name: upload_file
sha1: e62fbe82dc5c1efbdecfd94791e023002d3c178b
sha256: e24f69aa8738d14b85ad76a1783d51120b8b6ba467190fe7d8f96ad2969c8fdf
sha512: d4c7e45c2f509e43b521bfbcd67474ef271fa12088f7a57794ba866cdd41ddd3e9ee8fc776b31dd0a0811e62542b813e97c0f3404f4e416066c1338193f7f6c7
ssdeep: 49152:Q6otv8NVQqr7XXpwM+DbhzFG13Dyz6fRG+A+85fbhl7zsPS0mc+8aun:QDB8XQqDXf+D9FG1dp9m5fb37zsf+yn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014 AVG Technologies CZ, s.r.o.
InternalName: aswQuick.exe
FileVersion: 17.3.3443.0
CompanyName: AVG Technologies CZ, s.r.o.
ProductName: AVG Internet Security System
ProductVersion: 17.3.3443.0
FileDescription: AVG Virus scanner
OriginalFilename: aswQuick.exe
Translation: 0x0409 0x04e4

Ransom:Win32/NetWalker.MLS!MTB also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.43568561
FireEyeGeneric.mg.ccede1200a6e8eff
Qihoo-360Generic/HEUR/QVM18.1.E943.Malware.Gen
ALYacTrojan.Ransom.Avaddon
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.DelShad.4!c
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.43568561
K7GWTrojan ( 004befdb1 )
TrendMicroRansom_NetWalker.R06BC0DGV20
BitDefenderThetaGen:NN.ZexaF.34144.i!1@aKnPDJaO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.DelShad.dva
AlibabaRansom:Win32/NetWalker.0d5d3f89
ViRobotTrojan.Win32.Z.Netwalker.2229144
RisingPUF.Pack-Enigma!1.BA33 (CLOUD)
Ad-AwareTrojan.GenericKD.43568561
EmsisoftTrojan.GenericKD.43568561 (B)
F-SecureTrojan.TR/DelShad.djauj
Invinceaheuristic
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
WebrootW32.Malware.Gen
AviraTR/DelShad.djauj
MAXmalware (ai score=99)
ArcabitTrojan.Generic.D298CDB1
ZoneAlarmTrojan.Win32.DelShad.dva
MicrosoftRansom:Win32/NetWalker.MLS!MTB
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!CCEDE1200A6E
VBA32Trojan.Inject
MalwarebytesTrojan.Injector.Enigma
PandaTrj/CI.A
TrendMicro-HouseCallRansom_NetWalker.R06BC0DGV20
IkarusTrojan.Win32.Enigma
eGambitUnsafe.AI_Score_99%
GDataWin32.Trojan.Kryptik.6E9GI0
AVGWin32:Malware-gen
Cybereasonmalicious.2dc5c1
AvastWin32:Malware-gen

How to remove Ransom:Win32/NetWalker.MLS!MTB?

Ransom:Win32/NetWalker.MLS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment