Ransom

Should I remove “Ransom:Win32/QilinCrypt.PA!MTB”?

Malware Removal

The Ransom:Win32/QilinCrypt.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/QilinCrypt.PA!MTB virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine Ransom:Win32/QilinCrypt.PA!MTB?


File Info:

name: 6A93E618E467ED13F988.mlw
path: /opt/CAPEv2/storage/binaries/e90bdaaf5f9ca900133b699f18e4062562148169b29cb4eb37a0577388c22527
crc32: FCCF2F57
md5: 6a93e618e467ed13f98819172e24fffa
sha1: d34550ebc2bee47c708c8e048eb78881468e6bca
sha256: e90bdaaf5f9ca900133b699f18e4062562148169b29cb4eb37a0577388c22527
sha512: ac78fcd5ab3340fa691eb9941c729a58291ae58372ed8f535ae2a7ac23b99b0f57448343a020b4e889a7b7a822d116df32c8c5c14a4def0720987c2d6b966192
ssdeep: 24576:KBz37bSK2rgyik2VZGiOYnSadiUm6M551SaJkqFYUe3xHj96khwkyITnoXlIEvXX:Kx6Rvik2VUKnzhQ4akWXUy
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T156759E09FD83AA6AC5BF1970206FB376EA3D881405158E73D7E88D70BA1F3216D9871D
sha3_384: a7d543407817803e0a451edd4c3fd12fba5e4c4fd7fd5a3728b1eaf9138a97847d520ccf8f780bac49d14d09ff3eef26
ep_bytes: c7059881580000000000e9a1fcffff90
timestamp: 2022-09-13 09:55:04

Version Info:

0: [No Data]

Ransom:Win32/QilinCrypt.PA!MTB also known as:

LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.38057
McAfeeGenericRXAA-AA!6A93E618E467
CylanceUnsafe
VIPREGen:Variant.Babar.38057
SangforTrojan.Win32.Agent_AGen.AAC
K7AntiVirusTrojan ( 005984761 )
AlibabaRansom:Win32/QilinCrypt.2f76f791
K7GWTrojan ( 005984761 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/ABRisk.MYBY-9093
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Agent_AGen.AAC
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.xaqpzo
BitDefenderGen:Variant.Babar.38057
NANO-AntivirusTrojan.Win32.Redcap.jsmsnf
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.115e24af
Ad-AwareGen:Variant.Babar.38057
SophosMal/Generic-S + Troj/Ransom-GSU
F-SecureTrojan.TR/Redcap.jsalg
ZillyaTrojan.Agent.Win32.3010432
TrendMicroRansom.Win32.AGENDA.THIAFBB
McAfee-GW-EditionBehavesLike.Win32.Injector.th
FireEyeGen:Variant.Babar.38057
EmsisoftGen:Variant.Babar.38057 (B)
GDataGen:Variant.Babar.38057
JiangminTrojan.Agent.eggq
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Redcap.jsalg
MAXmalware (ai score=88)
Antiy-AVLTrojan[Ransom]/Win32.Babuk
KingsoftWin32.Troj.Agent.(kcloud)
ArcabitTrojan.Babar.D94A9
ZoneAlarmTrojan.Win32.Agent.xaqpzo
MicrosoftRansom:Win32/QilinCrypt.PA!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.QilinCrypt.C5240488
ALYacTrojan.Ransom.Filecoder
MalwarebytesRansom.FileCryptor
TrendMicro-HouseCallRansom.Win32.AGENDA.THIAFBB
RisingRansom.Agenda!1.E030 (CLASSIC)
IkarusTrojan-Ransom.Agenda
MaxSecureTrojan.Malware.188144452.susgen
FortinetW32/Agent_AGen.AAC!tr.ransom
AVGWin32:Malware-gen
PandaTrj/RansomGen.A

How to remove Ransom:Win32/QilinCrypt.PA!MTB?

Ransom:Win32/QilinCrypt.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment