Ransom.Ryuk is Malwarebytes’ detection name for a type of ransomware that is used in targeted attacks against enterprises and organizations.
Type and source of infection
Ransomware is a category of malware that holds files or systems hostage for ransom.
Ransom.Ryuk is used in targeted attacks, where the threat actors make sure that essential files are encrypted so they can ask for large ransom amounts. This means the attackers first find a way into the networks and use tools to map them out.
Because of the targeted nature of this ransomware, it is advised to do a full network scan to find any backdoors or other tools that the threat actors may have left behind, and which may enable them to regain access to the network.
Malwarebytes protects business and home users from Ransom.Ryuk by using Anti-Ransomware technology and real-time protection.
Malwarebytes blocks Ransom.Ryuk
Malwarebytes can detect and remove Ransom.Ryuk on business machines without further user interaction.
To remove Ransom.Ryuk using Malwarebytes business products, follow the instructions below.
How to remove Ransom.Ryuk with Malwarebytes Endpoint Protection
- Go to the Malwarebytes Cloud console.
- To allow you to invoke a scan while the machine is off the network, go to Settings > Policies > your policy > General.
- Under Endpoint Interface Options, turn ON:
- Show Malwarebytes icon in notification area
- Allow users to run a Threat Scan (all threats will be quarantined automatically)
- Temporarily enable Anti-Rootkit scanning for all invoked threat scans.
Go to Settings > Policies > your policy > Endpoint Protection > Scan Options
- Set Scan Rootkits to ON.
- Once the endpoint has been updated with the latest policy changes:
- Take the client off the network
- From the system tray icon, run an Anti-Rootkit threat scan.
If you have infected machines that are not registered endpoints in Malwarebytes Endpoint Protection, you can remove Ransom.Ryuk with our Breach Remediation tool (MBBR).
- Log into your My Account page and copy your license key. The key is needed to activate MBBR tool.
- Open your Cloud console.
- From a clean and safe machine, go to Endpoints > Add > Malwarebytes Breach Remediation. This will download the MBBR zip package.
- Unzip the package.
- Access a Windows command line prompt and issue the following commands:
mbbr register –key:<prodkey>
Note: You must substitute your license key for <prodkey>.
- Copy the MBBR folder to a flash drive.
- From an infected, offline machine, copy the MBBR folder from the flash drive.
- Start a scan using the following command:
mbbr scan –full –ark –remove –noreboot
- Refer to the Malwarebytes Breach Remediation Windows Administrator Guide for all supported scanning commands.
How to remove Ryuk with Malwarebytes Endpoint Security
You can use Malwarebytes Anti-Malware v1.80, which is included in your Malwarebytes Endpoint Security deployment to scan and remove Ransom.Ryuk.
- Remove the infected endpoint from the network.
- On the infected machine, right click the system tray icon and click on Start Scanner.
- Select Perform full scan.
- Click on Scan button.
- Open CMD
- CD to C:\Program Files (x86)\Malwarebytes’ Anti-Malware
- Run mbamapi /scan –full –remove -reboot