Ransom

Ransom:Win32/Ouroboros.GG!MTB removal guide

Malware Removal

The Ransom:Win32/Ouroboros.GG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Ouroboros.GG!MTB virus can do?

  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Ouroboros.GG!MTB?


File Info:

crc32: 7D0F1A3C
md5: 7bc5183b207888e9c01193fe2f1d0976
name: tmp77kqlrl8
sha1: e679f69eb28ab3462cc308143d9d372b40d936d1
sha256: 9e3d7b2163b865375d1b14a37c9130c55b9de8a6eb74b54f0d6f1a8b820eceae
sha512: ce38603c3e21a716124bc4cc627f3c983685849625ec2cec5a1391eb904a84dff8681204cc3944c73e19c4398ed37fb8658927ed0f953c037afea98eea989aaf
ssdeep: 24576:9x4N29GnianyRuF76EPXmlc8mTCFy/rd4n:9x21iyycZXmluOY/rd4n
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Ouroboros.GG!MTB also known as:

DrWebTrojan.Encoder.31534
MicroWorld-eScanGen:Heur.Ransom.Imps.1
FireEyeGen:Heur.Ransom.Imps.1
CAT-QuickHealTrojan.CryprenRI.S12908246
Qihoo-360Win32/Trojan.Ransom.2ba
McAfeeRansomware-GYP!7BC5183B2078
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.14177
AegisLabTrojan.Win32.Crypren.j!c
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Heur.Ransom.Imps.1
K7GWTrojan ( 005640be1 )
K7AntiVirusTrojan ( 005640be1 )
ArcabitTrojan.Ransom.Imps.1
TrendMicroRansom_VoidCrypt.R002C0DDI20
BitDefenderThetaGen:NN.ZexaF.34126.!uW@a4FXDrji
CyrenW32/Ransom.MQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Ouroboros.E
TrendMicro-HouseCallRansom.Win32.OUROBOROS.SMJK
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Crypren.agur
AlibabaRansom:Win32/Ouroboros.ab84866f
NANO-AntivirusTrojan.Win32.Encoder.hiqsil
TencentMalware.Win32.Gencirc.1154fd71
Ad-AwareGen:Heur.Ransom.Imps.1
EmsisoftGen:Heur.Ransom.Imps.1 (B)
F-SecureTrojan.TR/AD.OuroborosRansom.fxkau
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
IkarusTrojan-Ransom.Ouroboros
F-ProtW32/Ransom.MQ.gen!Eldorado
JiangminTrojan.Gen.atf
AviraTR/AD.OuroborosRansom.fxkau
Antiy-AVLTrojan[Ransom]/Win32.Limbozar
MicrosoftRansom:Win32/Ouroboros.GG!MTB
ZoneAlarmTrojan-Ransom.Win32.Crypren.agur
GDataGen:Heur.Ransom.Imps.1
AhnLab-V3Trojan/Win32.FileCoder.R333162
VBA32BScope.Trojan.DelShad
ALYacTrojan.Ransom.Ouroboros
MAXmalware (ai score=100)
MalwarebytesRansom.Ouroboros
PandaTrj/GdSda.A
APEXMalicious
RisingRansom.Agent!1.C4E7 (CLOUD)
YandexTrojan.Filecoder!/hLdfkeC3Qs
eGambitUnsafe.AI_Score_99%
FortinetW32/Ouroboros.E!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.b20788
AvastWin32:RansomX-gen [Ransom]

How to remove Ransom:Win32/Ouroboros.GG!MTB?

Ransom:Win32/Ouroboros.GG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment