Ransom

Ransom:Win64/Ryuk.PA!MTB information

Malware Removal

The Ransom:Win64/Ryuk.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win64/Ryuk.PA!MTB virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win64/Ryuk.PA!MTB?


File Info:

crc32: 4095B981
md5: a1da1e6d4a38aeb60cfefd39a104a276
name: A1DA1E6D4A38AEB60CFEFD39A104A276.mlw
sha1: bcd7046feae40c606c08793f56ba22dc08fd190e
sha256: 5a03953bd1f065445708540b86f71d81c7ac4691a4b0dc253bbfb5ab09c56dad
sha512: de0ab3287e500e952133a087033a8d716e05816c276cb4389a0b925db74a6e34ad3602e4f4cf1c4704a151b605e6473d7c876d8e223b3a58d268087ab1fdacc6
ssdeep: 3072:PCm4VVLZOJXkLSIPH+R+2L6cqRGEjyO18:qxTL4kHP++iG18
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win64/Ryuk.PA!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.Ryuk.3C2EBE68
FireEyeGeneric.mg.a1da1e6d4a38aeb6
CAT-QuickHealTrojan.Bayrob
ALYacTrojan.Ransom.Ryuk
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGeneric.Ransom.Ryuk.3C2EBE68
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/FileCoder.C.gen!Eldorado
SymantecRansom.Ryuk
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Ryuk-6892922-0
KasperskyHEUR:Trojan.Win32.Bayrob.pef
AlibabaRansom:Win64/Bayrob.1ed13f6d
NANO-AntivirusTrojan.Win32.Bayrob.ikieek
TencentWin32.Trojan.Bayrob.Lmuk
Ad-AwareGeneric.Ransom.Ryuk.3C2EBE68
EmsisoftGeneric.Ransom.Ryuk.3C2EBE68 (B)
ComodoMalware@#1tgilonvzl1l
F-SecureTrojan.TR/Ransom.Ryuk.onksu
TrendMicroRansom.Win32.RYUK.SMG
McAfee-GW-EditionBehavesLike.Win32.Injector.ct
SophosMal/Generic-S
IkarusTrojan-Ransom.Ryuk
AviraTR/Ransom.Ryuk.onksu
eGambitUnsafe.AI_Score_93%
MicrosoftRansom:Win64/Ryuk.PA!MTB
ArcabitGeneric.Ransom.Ryuk.3C2EBE68
ZoneAlarmHEUR:Trojan.Win32.Bayrob.pef
GDataWin32.Trojan-Ransom.Filecoder.CF@gen
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Cryptor.R352667
Acronissuspicious
McAfeeRansom-Ryuk!A1DA1E6D4A38
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Cryptor
MalwarebytesRansom.Ryuk
PandaTrj/Genetic.gen
ESET-NOD32a variant of Generik.WTGZXG
TrendMicro-HouseCallRansom.Win32.RYUK.SMG
RisingRansom.Ryuk!1.B855 (CLOUD)
YandexTrojan.GenAsa!YDOl+6P/vDM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ryuk.F!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34590.mqW@aqM218o
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.d4a38a
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Ryuk.HwoCJlsA

How to remove Ransom:Win64/Ryuk.PA!MTB?

Ransom:Win64/Ryuk.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment