Ransom

Ransom:Win32/REntS.SIB!MTB removal guide

Malware Removal

The Ransom:Win32/REntS.SIB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/REntS.SIB!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Attempts to delete or modify volume shadow copies
  • Exhibits possible ransomware file modification behavior
  • Likely virus infection of existing system binary
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/REntS.SIB!MTB?


File Info:

name: 54D2428434CD1C0DA021.mlw
path: /opt/CAPEv2/storage/binaries/68c47183f2cee9a793ab921915446cfaea2da37668e6b88420618315da693aff
crc32: 1311174F
md5: 54d2428434cd1c0da021a4825a156554
sha1: cc0ff0e7215c181ebdd44280badbacae9188da4a
sha256: 68c47183f2cee9a793ab921915446cfaea2da37668e6b88420618315da693aff
sha512: ae40ce68797d70bdca6fca12ff16a5693443ced50fefcdaf40c3cf396a9b673a81dbc099d90ab4ac7c22df4e549e9e2277cca2d06a6a7b957a03cdfdc3109258
ssdeep: 12288:VvisNv6+OeO+OeNhBBhhBBLJy0oSQwWsC07FHi4rqY3AOusQE+GvML0sqB:VvisZ1y3SDvxC4umAZG6Zq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DE48C22FA87E4B2C5B301B24D2DB75976BEB8500B749FB777D80B2D1E71080AB15792
sha3_384: 4a9a944db1a2e8a3bdc9fa2681f6394099e48a8bb99cf8dbaa4284603ec91af0a55173035625caffb2cc463d9c41138b
ep_bytes: e8e4df0000e97ffeffff558bec83ec20
timestamp: 2017-12-01 16:15:15

Version Info:

0: [No Data]

Ransom:Win32/REntS.SIB!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
SangforRansom.Win32.REntS.SIB!MTB
K7AntiVirusTrojan ( 0051a7af1 )
BitDefenderGen:Heur.Ransom.REntS.Gen.1
K7GWTrojan ( 0051a7af1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NNZ
APEXMalicious
Paloaltogeneric.ml
AlibabaRansom:Win32/generic.ali2000010
TencentWin32.Trojan.Filecoder.Sxeo
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
TrendMicroRansom_REntS.R002C0DB222
McAfee-GW-EditionBehavesLike.Win32.Emotet.jh
FireEyeGeneric.mg.54d2428434cd1c0d
SophosTroj/Blind-A
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.Gen.oz
AviraADWARE/Amonetize.Gen7
MicrosoftRansom:Win32/REntS.SIB!MTB
GDataGen:Heur.Ransom.REntS.Gen.1
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Gen
McAfeeRDN/Ransom
MAXmalware (ai score=84)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_REntS.R002C0DB222
RisingRansom.Blind!1.B393 (CLOUD)
YandexTrojan.GenAsa!kMQMbXKiOHw
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.NNZ!tr
BitDefenderThetaGen:NN.ZexaF.34182.OuW@aWEXB0hi
AVGWin32:Trojan-gen
Cybereasonmalicious.434cd1
AvastWin32:Trojan-gen

How to remove Ransom:Win32/REntS.SIB!MTB?

Ransom:Win32/REntS.SIB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment