Ransom

Ransom:Win32/Cryptolocker.PAO!MTB removal tips

Malware Removal

The Ransom:Win32/Cryptolocker.PAO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Cryptolocker.PAO!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing

How to determine Ransom:Win32/Cryptolocker.PAO!MTB?


File Info:

name: C947B7798E98C632E14B.mlw
path: /opt/CAPEv2/storage/binaries/ca5b109f3f0834d74922af9dbb7473808683a6bbce2640aeeb20814e64e263ea
crc32: 400AF754
md5: c947b7798e98c632e14bc8922e36be21
sha1: 23a5fef9618c185a8f361350e3ea1522f81c3da8
sha256: ca5b109f3f0834d74922af9dbb7473808683a6bbce2640aeeb20814e64e263ea
sha512: 8d7bd6d9f7d9f7c652e3aa40ae09a62795a69ae07096e8c0413fe0362d2f8b77a3ab8f586a26e9ff01f4778099ae7cce0d68c49a2f6a002aebae1e1df255c307
ssdeep: 384:lro9vad4wZ6dZ4MAkKkIbOx5jw2cdYIRpchnl5yImbU7:lG5WkKjyTw2caV7yy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196A28010939DD3D8D6A1067067AD3EB7A8FEA9715F0F50BFE38012782960FC4A624B07
sha3_384: cf1f199fadbc9bdfcbd110103ece071489f31d8975621783d8e2822d8b261175be7c54f8266420afbdf444e3c92ec38e
ep_bytes: 558bec81ec00050000535657b90d0000
timestamp: 2019-02-15 08:55:22

Version Info:

0: [No Data]

Ransom:Win32/Cryptolocker.PAO!MTB also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Ransom.Magniber.D06CB909
FireEyeGeneric.mg.c947b7798e98c632
CAT-QuickHealTrojan.MultiRI.S21117873
ALYacGeneric.Ransom.Magniber.D06CB909
CylanceUnsafe
BitDefenderGeneric.Ransom.Magniber.D06CB909
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34638.bqW@ayn2xGg
CyrenW32/Magniber.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Magniber.H
Paloaltogeneric.ml
ClamAVWin.Ransomware.Magniber-9939771-0
KasperskyUDS:Trojan.Multi.GenericML.xnet
NANO-AntivirusTrojan.Win32.Ric.hsyigr
RisingDropper.Generic!8.35E (TFE:dGZlOgTZ3s8rLWsoog)
Ad-AwareGeneric.Ransom.Magniber.D06CB909
EmsisoftGeneric.Ransom.Magniber.D06CB909 (B)
McAfee-GW-EditionGenericRXGC-JU!C947B7798E98
SophosML/PE-A
APEXMalicious
GDataGeneric.Ransom.Magniber.D06CB909
JiangminTrojan.Multi.ghv
AviraTR/Dropper.Gen2
MicrosoftRansom:Win32/Cryptolocker.PAO!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.JU.R422488
Acronissuspicious
McAfeeGenericRXGC-JU!C947B7798E98
MAXmalware (ai score=83)
VBA32BScope.Trojan.Agentb
MalwarebytesMalware.AI.3337457501
PandaAdware/SecurityProtection
TencentWin32.Trojan.Filecoder.Syhr
YandexTrojan.GenAsa!q2PC60Zhsjk
SentinelOneStatic AI – Suspicious PE
FortinetW32/Magniber.H!tr.ransom
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]

How to remove Ransom:Win32/Cryptolocker.PAO!MTB?

Ransom:Win32/Cryptolocker.PAO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment