Ransom

Should I remove “Ransom:Win32/PlayCrypt.PA!MTB”?

Malware Removal

The Ransom:Win32/PlayCrypt.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/PlayCrypt.PA!MTB virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior

How to determine Ransom:Win32/PlayCrypt.PA!MTB?


File Info:

name: 6D4F93DCE13AA48BBE04.mlw
path: /opt/CAPEv2/storage/binaries/24c4099ad588f1fd6fd092a9f1e11c102474b7b84bbcc4309eb96e235f32734e
crc32: A58562B3
md5: 6d4f93dce13aa48bbe04132459b5ed3b
sha1: 13c8a51b5ae086d9fcbf7158235446bacb2e6d64
sha256: 24c4099ad588f1fd6fd092a9f1e11c102474b7b84bbcc4309eb96e235f32734e
sha512: e6b13b8e74ad3753b0d73a45089f0dd0864235bef2b47fd3ef85a2e3ce7043696092d27a5b027d92c0cc917246052aaa95752bcb15261cbef23f157831a22a64
ssdeep: 3072:ElCgCkdiuezfR7uZO13PEzeotYgw0GUXl2bxW1/9JLdC/fhKJ2yhnDuG:dgXyuE0zcUV2K91GEnnX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A048D25A7A3D176EA72053425E59FF5CA2839300B0189EBA7801F7969385F2E135F3F
sha3_384: 21d96d9e38a1709bd9f62eca42d15ec61916ea679ac74dd098bfdc79e0af4c290973a28ae574519f30ec37f4d3b8782f
ep_bytes: e8ec020000e97afeffff558beca104b0
timestamp: 2022-08-11 06:08:46

Version Info:

0: [No Data]

Ransom:Win32/PlayCrypt.PA!MTB also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
FireEyeGeneric.mg.6d4f93dce13aa48b
McAfeeGenericRXTX-CG!6D4F93DCE13A
CylanceUnsafe
VIPREGen:Variant.Fragtor.128395
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Fragtor.128395
CyrenW32/Filecoder.DP.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.OLT
APEXMalicious
KasperskyTrojan-Ransom.Win32.Agent.bard
NANO-AntivirusTrojan.Win32.FileCoder.jrlveh
MicroWorld-eScanGen:Variant.Fragtor.128395
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGen:Variant.Fragtor.128395
EmsisoftGen:Variant.Fragtor.128395 (B)
TrendMicroRansom_PlayCrypt.R06CC0DHF22
SophosML/PE-A
GDataGen:Variant.Fragtor.128395
Antiy-AVLTrojan/Generic.ASMalwS.1D6F
ArcabitTrojan.Fragtor.D1F58B
ZoneAlarmTrojan-Ransom.Win32.Agent.bard
MicrosoftRansom:Win32/PlayCrypt.PA!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5217612
ALYacGen:Variant.Fragtor.128395
MAXmalware (ai score=88)
MalwarebytesMalware.AI.4139276920
TrendMicro-HouseCallRansom_PlayCrypt.R06CC0DHF22
RisingTrojan.Generic@AI.91 (RDML:aFuoD3wGhT/VyhOHjI2NoQ)
YandexTrojan.GenAsa!DS+xdKjbUw0
SentinelOneStatic AI – Suspicious PE
BitDefenderThetaGen:NN.ZexaF.34606.lqW@aa!!A3b
AVGWin32:RansomX-gen [Ransom]
PandaTrj/GdSda.A

How to remove Ransom:Win32/PlayCrypt.PA!MTB?

Ransom:Win32/PlayCrypt.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment