Ransom

About “Ransom:Win32/Sorena.PA!MTB” infection

Malware Removal

The Ransom:Win32/Sorena.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Sorena.PA!MTB virus can do?

    How to determine Ransom:Win32/Sorena.PA!MTB?

    
    

    File Info:

    crc32: E922DBBF
    md5: c7e98cfdf6e3db405331cf6b38dc198a
    name: encrypt.exe
    sha1: 805d8c78c3dcc3db15499247b865f6bad473ed1f
    sha256: 80524ef85a8b932ff3d782663ba401b04e0d4baf17b2e4554464c7f436e48c6c
    sha512: b11d1cff3b35d2e5979bcae4ac839a845a2e8a30ab8724cc0c0ca6b550c0a276deb4f33041b84873de54efc8d66f2faa3b3521539d3956c6f92dcb2b23545a6f
    ssdeep: 49152:GaMN+taC6muU4cUW7riMMZEV3Aei9xPHobNYsA6FoWkQPlNyCMM:Ga2+ruU4cUWSM2EV3AvHaN3A6WWk04B
    type: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows

    Version Info:

    0: [No Data]

    Ransom:Win32/Sorena.PA!MTB also known as:

    MicroWorld-eScanGen:Variant.Ursu.747827
    FireEyeGen:Variant.Ursu.747827
    McAfeeArtemis!C7E98CFDF6E3
    CylanceUnsafe
    K7AntiVirusTrojan ( 005618c01 )
    BitDefenderGen:Variant.Ursu.747827
    K7GWTrojan ( 005618c01 )
    SymantecTrojan.Gen.MBT
    AvastWin64:Trojan-gen
    GDataGen:Variant.Ursu.747827
    KasperskyHEUR:Trojan.Win32.Generic
    AlibabaRansom:Win32/Sorena.736c1ddc
    ViRobotTrojan.Win32.Z.Ursu.2854400.B
    RisingRansom.Sorena!8.11795 (CLOUD)
    Ad-AwareGen:Variant.Ursu.747827
    SophosMal/Generic-S
    ComodoMalware@#2vnezz921277q
    F-SecureTrojan.TR/FileCoder.joxbq
    DrWebTrojan.Encoder.31868
    TrendMicroRansom.Win64.SORENA.SMDS
    EmsisoftGen:Variant.Ursu.747827 (B)
    IkarusTrojan-Ransom.FileCrypter
    CyrenW64/Trojan.AYVK-7016
    WebrootW32.Malware.Gen
    AviraTR/FileCoder.joxbq
    MAXmalware (ai score=100)
    Antiy-AVLTrojan[Ransom]/Win32.Sorena
    ArcabitTrojan.Ursu.DB6933
    ZoneAlarmHEUR:Trojan.Win32.Generic
    MicrosoftRansom:Win32/Sorena.PA!MTB
    CynetMalicious (score: 85)
    AhnLab-V3Malware/Win64.RL_Ransom.R333333
    ALYacTrojan.Ransom.Filecoder
    MalwarebytesRansom.HackForLife
    ESET-NOD32a variant of Win64/Filecoder.AY
    TrendMicro-HouseCallRansom.Win64.SORENA.SMDS
    TencentWin32.Trojan.Generic.Tbin
    FortinetW32/Sorena.AY!tr.ransom
    AVGWin64:Trojan-gen
    Paloaltogeneric.ml

    How to remove Ransom:Win32/Sorena.PA!MTB?

    Ransom:Win32/Sorena.PA!MTB removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment