Ransom

About “Ransom:Win32/Zudochka.C!MTB” infection

Malware Removal

The Ransom:Win32/Zudochka.C!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Zudochka.C!MTB virus can do?

  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk

How to determine Ransom:Win32/Zudochka.C!MTB?


File Info:

crc32: F026C46D
md5: b8018958476178596817f734894ff64c
name: B8018958476178596817F734894FF64C.mlw
sha1: e1cae0d2a320a2756ae1ee5d37bfe803b39853fa
sha256: 672fb249e520f4496e72021f887f8bb86fec5604317d8af3f0800d49aa157be1
sha512: 0bbdb28f2b5ac4a7965c542b7a62dc644aa0887ec8503200c4047a84dce6a924dfb8cbb8b08d1343bc8301c2e9cc544ac3b686d9e966200f082597b2b801be97
ssdeep: 12288:nZqE25BWr6q6zNPrSyg8A7YNpQH/vRoV:nZqEGBdqirVxCY4HnRU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Zudochka.C!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056037c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.30979
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.12366
SangforRansom.Win32.Zudochka.C!MTB
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0056037c1 )
CyrenW32/Trojan.OJBZ-7241
SymantecDownloader
ESET-NOD32a variant of Win32/Filecoder.OAE
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.vqe
BitDefenderDeepScan:Generic.Ransom.Cuba.097204E7
NANO-AntivirusTrojan.Win32.Encoder.gzskrv
MicroWorld-eScanDeepScan:Generic.Ransom.Cuba.097204E7
TencentWin32.Trojan.Gen.Pdlp
Ad-AwareDeepScan:Generic.Ransom.Cuba.097204E7
SophosMal/Generic-R + Troj/Ransom-GAY
ComodoMalware@#1jcq5s078z4gj
BitDefenderThetaGen:NN.ZexaF.34628.DuW@aeVhJ0ii
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.b801895847617859
EmsisoftDeepScan:Generic.Ransom.Cuba.097204E7 (B)
JiangminTrojan.Gen.aqd
WebrootW32.Gen.BT
AviraTR/FileCoder.vifbj
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Zudochka.C!MTB
ArcabitDeepScan:Generic.Ransom.Cuba.097204E7
AegisLabTrojan.Win32.Gen.j!c
ZoneAlarmTrojan-Ransom.Win32.Gen.vqe
GDataDeepScan:Generic.Ransom.Cuba.097204E7
McAfeeGenericRXKX-RM!B80189584761
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.83 (RDMK:2GPxh3mmkMp901XdIN+mYw)
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.74826057.susgen
FortinetW32/FileCoder.VNQBG!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cuba.HwoC0L8A

How to remove Ransom:Win32/Zudochka.C!MTB?

Ransom:Win32/Zudochka.C!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment