Ransom

About “Ransom:Win32/Paradise.BA!MTB” infection

Malware Removal

The Ransom:Win32/Paradise.BA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Paradise.BA!MTB virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Paradise.BA!MTB?


File Info:

crc32: 66A970DC
md5: a5e85cfd8cfcf3b65dbe303623954207
name: A5E85CFD8CFCF3B65DBE303623954207.mlw
sha1: b10dd0208181bc1369b048baa1fb2d411fe183bf
sha256: 2c5a08152fc1bb0bc1f4a4120126e803908754c681d8e883804fdc5610480ad1
sha512: e0aae9c9bcb369a783b95c8859419ea12f7404ebe02b364bb7c59fe5260a54a64e6c60598f3e9e922a19d0d9170690e8bd16e791687d6236de935df1fdad2a39
ssdeep: 96:nP7m4k9VxCEnN6GyHV7JxMdsC6G7hH3QlWq+l68uo/X:nnciEnNeVC6QAluJN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Paradise.BA!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00494a381 )
LionicVirus.Win32.Paradise.n!c
Elasticmalicious (high confidence)
DrWebWin32.Belcebu.2168
CynetMalicious (score: 100)
CAT-QuickHealW32.Iced.2168
ALYacWin32.Paradise.2168
CylanceUnsafe
ZillyaVirus.Paradise.Win32.1
SangforRansom.Win32.Paradise.2168
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Paradise.3d6be631
K7GWTrojan ( 00494a381 )
Cybereasonmalicious.d8cfcf
CyrenW32/Iced.2168
SymantecW95.Iced.2112
ESET-NOD32Win32/Paradise.2168
APEXMalicious
AvastWin32:Paradise
ClamAVWin.Trojan.Paradise-1
KasperskyVirus.Win32.Paradise.2168
BitDefenderWin32.Paradise.2168
NANO-AntivirusVirus.Win32.Paradise.bkig
MicroWorld-eScanWin32.Paradise.2168
TencentWin32.Virus.Paradise.Loro
Ad-AwareWin32.Paradise.2168
SophosMal/Generic-R + W32/Paradise-A
ComodoMalware@#1o6fgwdtova5i
BitDefenderThetaAI:FileInfector.6F6472DB13
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionW95/Iced.2168
FireEyeGeneric.mg.a5e85cfd8cfcf3b6
EmsisoftWin32.Paradise.2168 (B)
SentinelOneStatic AI – Suspicious PE
JiangminWin32/Paradise.2168
WebrootW32/Paradise-A
AviraW32/Paradise.2168
Antiy-AVLTrojan/Generic.ASSuf.66CD
MicrosoftRansom:Win32/Paradise.BA!MTB
GDataWin32.Paradise.2168
Acronissuspicious
McAfeeW95/Iced.2168
MAXmalware (ai score=100)
PandaW32/Iced.A
RisingWin32.Paradise (CLASSIC)
YandexWin32.Paradise.2168.B
IkarusVirus.Win32.Paradise
MaxSecureVirus.W32.Paradise.2116
FortinetW32/Iced.B
AVGWin32:Paradise
Qihoo-360Win32/Ransom.Paradise.HxQBEpsA

How to remove Ransom:Win32/Paradise.BA!MTB?

Ransom:Win32/Paradise.BA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment