Ransom

Ransom:Win32/Paradise.BC!MTB (file analysis)

Malware Removal

The Ransom:Win32/Paradise.BC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Paradise.BC!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to restart the guest VM
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Likely virus infection of existing system binary
  • Clears Windows events or logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Paradise.BC!MTB?


File Info:

crc32: A80CF34F
md5: 567204cbb8d1c5908a5316f9dfdcb353
name: 567204CBB8D1C5908A5316F9DFDCB353.mlw
sha1: cc7eca3c24883a3b563288c08cfab7cc248a0315
sha256: 54f6ec27eb7526c439d33e7592e4864842fccf950d828fe14ef7c8eb080ee371
sha512: ec4e2a03a525ae5150449d5403f2fc72b88d1cd977c503f4943b0889b82c543e46c35cd204fe27c5c03d4817bcc9413ec467637a038d2d7cd164d59d2b377f3b
ssdeep: 6144:NICjjI4WHB/8cQoASA0AVjq6g0uhq+r0+K248Bb+MNa:ai6hEcQoA50sbuPq24EbJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Paradise.BC!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35710827
FireEyeGeneric.mg.567204cbb8d1c590
CAT-QuickHealTrojan.Malexf
McAfeeRDN/Generic.hra
CylanceUnsafe
VIPRETrojan.FakeAlert
AegisLabTrojan.Win32.DelShad.4!c
SangforMalware
K7AntiVirusTrojan ( 00574a961 )
BitDefenderTrojan.GenericKD.35710827
K7GWTrojan ( 00574a961 )
CyrenW32/FakeAlert.DX.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.DelShad.foh
AlibabaRansom:Win32/generic.ali2000010
ViRobotTrojan.Win32.Z.Agent.456704.GL
Ad-AwareTrojan.GenericKD.35710827
SophosMal/Generic-R + Mal/EncPk-APW
ComodoMalware@#2ntorokt68wai
F-SecureTrojan.TR/AD.ZardRansom.twnbe
DrWebTrojan.Encoder.33321
TrendMicroTROJ_GEN.R049C0PLH20
McAfee-GW-EditionRDN/Generic.hra
EmsisoftTrojan.GenericKD.35710827 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/AD.ZardRansom.twnbe
MAXmalware (ai score=100)
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftRansom:Win32/Paradise.BC!MTB
GridinsoftRansom.Win32.Ransom.oa
ArcabitTrojan.Generic.D220E76B
ZoneAlarmTrojan.Win32.DelShad.foh
GDataTrojan.GenericKD.35710827
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34700.BmW@aGrpkkii
ALYacTrojan.Ransom.VegaLocker
VBA32BScope.Trojan.Glupteba
MalwarebytesRansom.Paradise
PandaTrj/Krap.AH
ESET-NOD32a variant of Win32/Kryptik.HIJC
TrendMicro-HouseCallTROJ_GEN.R049C0PLH20
YandexTrojan.DelShad!bnoPB2f9bQA
IkarusTrojan.Win32.Crypt
FortinetW32/DelShad.FOH!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Generic/HEUR/QVM19.1.EA42.Malware.Gen

How to remove Ransom:Win32/Paradise.BC!MTB?

Ransom:Win32/Paradise.BC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment