Ransom

Ransom:Win32/PlayCrypt.MP!MTB removal tips

Malware Removal

The Ransom:Win32/PlayCrypt.MP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/PlayCrypt.MP!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Ransom:Win32/PlayCrypt.MP!MTB?


File Info:

name: 20963A476928F3AAD040.mlw
path: /opt/CAPEv2/storage/binaries/f6072ff57c1cfe74b88f521d70c524bcbbb60c561705e9febe033f51131be408
crc32: 8413641B
md5: 20963a476928f3aad040affc4980e5f5
sha1: b1254d5069b4a38608d0724e2485701dd8bf0dc2
sha256: f6072ff57c1cfe74b88f521d70c524bcbbb60c561705e9febe033f51131be408
sha512: 5210082667863f6255142ecfb164ed78b97905ed7fe10562794073ddddb505d7600a8c0b4ac988a6f10f8f97d38cb68ccca0b69cfee082740c319bcfa5897c6b
ssdeep: 3072:4SNTPzB1fdiGuNbvAzJ7ZGNWmhOgLe4+zOWeIclqi+vUAzZhkj:7Vv/dcN3OaWFlzw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T141B34A13B1D19032D57A09301EE69BAA492CF8B54B105DEB33CC1D2F0FA16D1A537EAB
sha3_384: 115f8af7bb326331bc2ee0420679aace27a5b0d7c3d97f3dbf0b6f4308c300d823363fcb46793e3a5773838238b7ad4e
ep_bytes: e8ec020000e97afeffff558beca104a0
timestamp: 2022-07-25 00:55:15

Version Info:

0: [No Data]

Ransom:Win32/PlayCrypt.MP!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Play.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.328963
FireEyeGeneric.mg.20963a476928f3aa
CAT-QuickHealRansom.Play.S32038318
SkyhighBehavesLike.Win32.Generic.ch
McAfeeRDN/Ransom
Cylanceunsafe
SangforRansom.Win32.Play.V7kn
K7AntiVirusTrojan ( 005965841 )
AlibabaRansom:Win32/PlayCrypt.d3a32391
K7GWTrojan ( 005965841 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36744.gqW@ae9GUpo
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Filecoder.PLAY.A
APEXMalicious
KasperskyTrojan-Ransom.Win32.Play.f
BitDefenderGen:Variant.Fragtor.328963
AvastWin32:RansomX-gen [Ransom]
TencentMalware.Win32.Gencirc.10bdf743
SophosMal/Generic-S
F-SecureTrojan.TR/FileCoder.lbjni
DrWebTrojan.Encoder.35815
ZillyaTrojan.Filecoder.Win32.25780
TrendMicroRansom.Win32.PLAYDE.YXCHJT
EmsisoftGen:Variant.Fragtor.328963 (B)
IkarusTrojan-Ransom.FileCrypter
GDataGen:Variant.Fragtor.328963
JiangminTrojan.Agent.ebrx
WebrootW32.Ransomware.Gen
GoogleDetected
AviraTR/FileCoder.lbjni
VaristW32/ABRisk.LEPU-0253
Antiy-AVLTrojan/Win32.Filecoder
Kingsoftmalware.kb.a.780
ArcabitTrojan.Fragtor.D50503
ViRobotTrojan.Win32.S.Filecoder.113152
ZoneAlarmTrojan-Ransom.Win32.Play.f
MicrosoftRansom:Win32/PlayCrypt.MP!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5236854
ALYacTrojan.Ransom.Filecoder
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.PLAYDE.YXCHJT
RisingTrojan.Generic@AI.99 (RDML:zeDO5QrCKfaWQ5GAGRy07Q)
YandexTrojan.GenAsa!DS+xdKjbUw0
MaxSecureTrojan.Malware.12310942.susgen
FortinetW32/Filecoder.PLAY!tr.ransom
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS

How to remove Ransom:Win32/PlayCrypt.MP!MTB?

Ransom:Win32/PlayCrypt.MP!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment