Ransom

Ransom:Win32/Zeoticus.PA!MTB removal guide

Malware Removal

The Ransom:Win32/Zeoticus.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Zeoticus.PA!MTB virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Likely installs a bootkit via raw harddisk modifications
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Zeoticus.PA!MTB?


File Info:

crc32: 43845309
md5: b8cad5b6d5ccd1504914558f87553bdc
name: B8CAD5B6D5CCD1504914558F87553BDC.mlw
sha1: 36b1f918bbdc9ae03d457081403865ab37568044
sha256: 7c3e39ba2c6035d737bfb124949053ec2fe8837722e50de3088749a71c21fb4f
sha512: e188f9a54bfcc14916256477e10fdc3ccc719b2213fd12e3e03a02e3e6a1760b3edfcc685a1130e3e621b58327dbfe2c8483ec1c3f953c3369c93906f9d236bc
ssdeep: 3072:NfauJ/DusaUmZMor4uXwluZJxToIch+m930EBQkNQWTBfMYkTd3zHZ0DELbT:9bJ/xhuXwl0JdtcFZ6kNQWTB0vV50DE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Zeoticus.PA!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00564d931 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33303
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Zeoticus
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.17852
SangforRansom.Win32.Zeoticus.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Zeoticus.a93fa631
K7GWTrojan ( 00564d931 )
Cybereasonmalicious.6d5ccd
CyrenW32/Trojan.YYBZ-4230
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OBQ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyPacked.Win32.Krap.b
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
TencentWin32.Trojan.Filecoder.Piac
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
BitDefenderThetaAI:Packer.313DE4CC1F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WBJ21
McAfee-GW-EditionRDN/Ransom
FireEyeGeneric.mg.b8cad5b6d5ccd150
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Krap.Gen.a
AviraTR/FileCoder.tqqai
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Zeoticus.PA!MTB
ArcabitTrojan.Ransom.REntS.Gen.1
AegisLabHacktool.Win32.Krap.x!c
GDataWin32.Trojan-Ransom.Zeoticus.A
TACHYONRansom/W32.Zeoticus.190464
AhnLab-V3Packed/Win32.Krap.C4277008
Acronissuspicious
McAfeeRDN/Ransom
MAXmalware (ai score=100)
VBA32BScope.Trojan.Staser
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WBJ21
RisingDropper.Dinwod!8.3BD (CLOUD)
YandexTrojan.Filecoder!ahctOpysAb4
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.19082.susgen
FortinetW32/Filecoder.7D54!tr.ransom
AVGWin32:MalwareX-gen [Trj]

How to remove Ransom:Win32/Zeoticus.PA!MTB?

Ransom:Win32/Zeoticus.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment