Ransom

Ransom:Win32/NetWalker!MTB removal tips

Malware Removal

The Ransom:Win32/NetWalker!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/NetWalker!MTB virus can do?

  • Attempts to delete volume shadow copies
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/NetWalker!MTB?


File Info:

crc32: 0AF20BED
md5: bde3ec20e9f8253524fa74aeb65681ba
name: BDE3EC20E9F8253524FA74AEB65681BA.mlw
sha1: 1ade5bf755530e16c631106bf266c4632c372c34
sha256: 882e89ea1b8d70646bdf6476d8cb46991b950f27e03e93bf49ea3209c2d69581
sha512: 1d152ab20b03cd74021810a9739dd0c1a03f2bcb87fde9f4926d07d330c9f8517a9fa5c16cb0046f59c13c92bfc7e23e9aeb6924dea66ae2a61eb50fb0daaf9d
ssdeep: 1536:1OY1GfOoGFpMn6UUTWReJAINl98PavEdfh8:IRfO3Fp86vCReJA+l986EZh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/NetWalker!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056346a1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Mailto.P5
ALYacTrojan.Ransom.Mailto
MalwarebytesMalware.AI.3109941196
ZillyaTrojan.Filecoder.Win32.14719
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/NetWalker.cae6b92b
K7GWTrojan ( 0056346a1 )
Cybereasonmalicious.0e9f82
CyrenW32/Netwalker.A.gen!Eldorado
SymantecDownloader
ESET-NOD32a variant of Win32/Filecoder.NetWalker.D
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Mailto.vho
BitDefenderGeneric.Ransom.Netwalker.23A8D047
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGeneric.Ransom.Netwalker.23A8D047
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.Netwalker.23A8D047
SophosMal/Generic-R + Troj/Netwalk-A
ComodoMalware@#2zsfap24o5mih
BitDefenderThetaAI:Packer.CAEF39D71E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.NETWALKER.SMTH
McAfee-GW-EditionBehavesLike.Win32.RansomCWall.kh
FireEyeGeneric.mg.bde3ec20e9f82535
EmsisoftGeneric.Ransom.Netwalker.23A8D047 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Mailto.i
AviraHEUR/AGEN.1115135
MicrosoftRansom:Win32/NetWalker!MTB
AegisLabTrojan.Win32.Mailto.j!c
GDataGeneric.Ransom.Netwalker.23A8D047
AhnLab-V3Trojan/Win32.RansomCrypt.C4029970
McAfeeRansom-NetW!BDE3EC20E9F8
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Spy
PandaTrj/CI.A
TrendMicro-HouseCallRansom.Win32.NETWALKER.SMTH
RisingRansom.Agent!1.C0B5 (CLOUD)
YandexTrojan.Filecoder!V8/mtpsqf8A
IkarusTrojan-Ransom.NetWalker
FortinetW32/NetWalker.B!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Virus.Walker.HxQBaGAA

How to remove Ransom:Win32/NetWalker!MTB?

Ransom:Win32/NetWalker!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment