Ransom

About “Ransom:Win32/WannaCrypt.DA!MTB” infection

Malware Removal

The Ransom:Win32/WannaCrypt.DA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/WannaCrypt.DA!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ransom:Win32/WannaCrypt.DA!MTB?


File Info:

name: 4885C845EC854BE88E1C.mlw
path: /opt/CAPEv2/storage/binaries/014970e3cac6dc1d6d85cea6734aa4155a15e0ca6c961aa5930ba1cdb4d6ff0f
crc32: 2B1661D6
md5: 4885c845ec854be88e1ce577d37e1c33
sha1: 5cc405a2a4facd79628736e3a097778fef680f1a
sha256: 014970e3cac6dc1d6d85cea6734aa4155a15e0ca6c961aa5930ba1cdb4d6ff0f
sha512: bfab583b5046a9d272413008d656ca72d072774215031b40d69e03ab5c72a87fa6f95974ee8f80a1abb29e1a1e4ae9a526241f53fb74904bbed51e699b0ee5a2
ssdeep: 49152:LMSPbcBVs/1INRx+TSqTdX1HkQo6SAARdhnvm:LPoBK1aRxcSUDk36SAEdhvm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1869533F5B0B256B8E3062D7444AFDA5376D5707A35EB3D11EF8008B9B896E5BD3802C2
sha3_384: 7ff6e74692e6e08b9e4988401eb44f10b9ac50ca9c2d734aa0f95acadddbf2799d94dad1bb3d79d4bca104e4fa13d8e2
ep_bytes: b139cba1d062aa4f875e1693b609ef62
timestamp: 2015-09-20 19:44:01

Version Info:

0: [No Data]

Ransom:Win32/WannaCrypt.DA!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Wanna.tpUE
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.22783564
FireEyeGeneric.mg.4885c845ec854be8
CAT-QuickHealTrojan.GenericPMF.S16335961
ALYacTrojan.Generic.22783564
CylanceUnsafe
K7AntiVirusRansomware ( 00542db01 )
AlibabaRansom:Win32/Agentb.dbe
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5ec854
VirITTrojan.Win32.Encoder.QXS
CyrenW32/Trojan.UUBY-7729
SymantecSMG.Heur!gen
ESET-NOD32Win32/Filecoder.WannaCryptor.N
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Wannacry-6803937-0
KasperskyTrojan-Ransom.Win32.Wanna.apno
BitDefenderTrojan.Generic.22783564
NANO-AntivirusTrojan.Win32.Wanna.forlua
SUPERAntiSpywareRansom.Crypt/Variant
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10ba4438
Ad-AwareTrojan.Generic.22783564
EmsisoftTrojan.Generic.22783564 (B)
ComodoTrojWare.Win32.Ransom.WannaCry.SU@83tnqe
DrWebTrojan.Encoder.11432
ZillyaTrojan.Rasftuby.Win32.241
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=81)
MicrosoftRansom:Win32/WannaCrypt.DA!MTB
GDataTrojan.Generic.22783564
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.WannaCryptor.R229339
McAfeeGenericRXDX-QB!4885C845EC85
TACHYONRansom/W32.Agent.2061938
VBA32TrojanRansom.Wanna
MalwarebytesWannaCry.Ransom.Encrypt.DDS
RisingTrojan.Win32.Rasftuby.a (CLASSIC)
YandexTrojan.Agent!18Ax3m9d6Qc
IkarusTrojan-Ransom.WannaCrypt
FortinetW32/GenericRXDR.TD!tr
AVGWin32:Malware-gen

How to remove Ransom:Win32/WannaCrypt.DA!MTB?

Ransom:Win32/WannaCrypt.DA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment