Ransom

Ransom:Win32/OutSideCrypt.PA!MTB removal

Malware Removal

The Ransom:Win32/OutSideCrypt.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/OutSideCrypt.PA!MTB virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Likely virus infection of existing system binary
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/OutSideCrypt.PA!MTB?


File Info:

crc32: 5B59708C
md5: 6c1af4d7b52d136dade27ea96186ca7c
name: 6C1AF4D7B52D136DADE27EA96186CA7C.mlw
sha1: bb6d6952514d80e108396e2b790b2faca0c1c515
sha256: 01049b0cf7f2a1cab769b71d6d75b60124e423f91c5c26af07fd8cd527cf6e5a
sha512: 385f6af48381fe6cffe0626ce15a38e0c1399a25a66c1cf44b3018ab3449faf95e7b91c001b7a766e8abdd5d80c5a17ba7091140a513d400529c9f0281bcd4a7
ssdeep: 3072:j+vAsrigLjpMr4sZoHBuG2GHRsvbyHyA4EyvEyVk8yL8CVYyE+AasGIi0O2oGM6:iTJpMr9k72GHR1yvEyvEyV3s8pDi9Ua
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1017
InternalName: FILE.EXE
FileVersion: 2.0.2.0
CompanyName: NoName
ProductName:
ProductVersion: 2.0.2.0
FileDescription:
OriginalFilename: FILE.EXE
Translation: 0x0409 0x04b0

Ransom:Win32/OutSideCrypt.PA!MTB also known as:

K7AntiVirusTrojan ( 005768651 )
Elasticmalicious (high confidence)
CynetMalicious (score: 85)
CAT-QuickHealTrojan.AntiAV
ALYacTrojan.GenericKD.36248748
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.17555
SangforTrojan.Win32.Ymacco.AA01
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000027
K7GWTrojan ( 005768651 )
Cybereasonmalicious.7b52d1
CyrenW32/Trojan.QNFF-7588
SymantecDownloader
ESET-NOD32Win32/Filecoder.Outsider.J
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan.Win32.AntiAV
BitDefenderTrojan.GenericKD.36248748
NANO-AntivirusTrojan.Win32.AntiAV.iiqaur
MicroWorld-eScanTrojan.GenericKD.36248748
TencentWin32.Trojan.Filecoder.Woqc
Ad-AwareTrojan.GenericKD.36248748
SophosMal/Generic-S
ComodoMalware@#2484x7vma88xo
F-SecureHeuristic.HEUR/AGEN.1116537
BitDefenderThetaGen:NN.ZexaF.34670.mu0@aawLWHhi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.YMACCO.USASHAQ21
McAfee-GW-EditionGenericRXNK-AG!6C1AF4D7B52D
FireEyeTrojan.GenericKD.36248748
EmsisoftTrojan.GenericKD.36248748 (B)
JiangminTrojan.AntiAV.ebq
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1116537
Antiy-AVLTrojan[Ransom]/Win32.Outsider
MicrosoftRansom:Win32/OutSideCrypt.PA!MTB
ArcabitTrojan.Generic.D2291CAC
AegisLabTrojan.Win32.AntiAV.4!c
ZoneAlarmHEUR:Trojan.Win32.AntiAV
GDataTrojan.GenericKD.36248748
AhnLab-V3Malware/Win32.Generic.C3680047
McAfeeGenericRXNK-AG!6C1AF4D7B52D
MAXmalware (ai score=88)
VBA32BScope.Adware.Foxiebro
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.YMACCO.USASHAQ21
RisingTrojan.Filecoder!8.68 (CLOUD)
YandexTrojan.AntiAV!PpQEFojL29M
IkarusTrojan-Ransom.Outsider
FortinetW32/AntiAV.J!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.AntiAV.HwoChmsA

How to remove Ransom:Win32/OutSideCrypt.PA!MTB?

Ransom:Win32/OutSideCrypt.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment