Ransom

Ransom:Win32/Ryuk.DA!MTB malicious file

Malware Removal

The Ransom:Win32/Ryuk.DA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Ryuk.DA!MTB virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Exhibits possible ransomware file modification behavior

How to determine Ransom:Win32/Ryuk.DA!MTB?


File Info:

crc32: A41DDBB8
md5: 7ba20fce7ac259f6062f73290c2e28cf
name: 7BA20FCE7AC259F6062F73290C2E28CF.mlw
sha1: 2200dd0c27630aaa7ff164da0fc3dd080a4a7f9c
sha256: 1a5d66450670c057bce6eff656b86dce21e729c46c86362ed50fe79c1b074f15
sha512: ba119a3727abb2955aaa88f6d5f9d3190d669b95f1f326d4fa81fd5a1e6387c765736e9637661acb4dc512d73067380a0afd5a540016777e7a88972e8cd5c717
ssdeep: 1536:D1I9OWPAjmAZJmxPS30BiGChsed5zcHAQ1sf:5kO5ZJmviGChFFQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Ryuk.DA!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Peed.2.86508538
ALYacTrojan.Ransom.Ryuk
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Cryptor.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056854b1 )
BitDefenderDeepScan:Generic.Peed.2.86508538
K7GWTrojan ( 0056854b1 )
Cybereasonmalicious.e7ac25
ArcabitDeepScan:Generic.Peed.2.86508538
CyrenW32/Trojan.IGIJ-4929
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Conti.D
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Ransom.Win32.Cryptor.vho
AlibabaRansom:Win32/Cryptor.f9afa46f
NANO-AntivirusTrojan.Win32.Cryptor.htngyb
ViRobotTrojan.Win32.S.Conti.90112
TencentWin32.Trojan.Cryptor.Akpe
Ad-AwareDeepScan:Generic.Peed.2.86508538
EmsisoftDeepScan:Generic.Peed.2.86508538 (B)
F-SecureTrojan.TR/FileCoder.dbwhx
DrWebTrojan.Encoder.32558
ZillyaTrojan.Cryptor.Win32.552
TrendMicroRansom.Win32.CONTI.SMW
McAfee-GW-EditionBehavesLike.Win32.Emotet.mh
FireEyeGeneric.mg.7ba20fce7ac259f6
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Cryptor.ru
AviraTR/FileCoder.dbwhx
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Cryptor
MicrosoftRansom:Win32/Ryuk.DA!MTB
ZoneAlarmHEUR:Trojan-Ransom.Win32.Cryptor.vho
GDataDeepScan:Generic.Peed.2.86508538
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Filecoder.C4194000
McAfeeRansom-Conti!7BA20FCE7AC2
VBA32BScope.Trojan.StartPage
MalwarebytesRansom.Ryuk
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.CONTI.SMW
RisingRansom.Filecoder!8.55A8 (TFE:4:qE2UhMjnJ6M)
YandexTrojan.Filecoder!ZdZ84RO5jYE
IkarusTrojan-Ransom.Conti
FortinetW32/Cryptor.CDDC!tr.ransom
BitDefenderThetaAI:Packer.8625D1EA1F
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.Filecoder.HxQBBJsA

How to remove Ransom:Win32/Ryuk.DA!MTB?

Ransom:Win32/Ryuk.DA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment