Ransom

Generic.Ransom.DMALock.3D21159A (file analysis)

Malware Removal

The Generic.Ransom.DMALock.3D21159A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.DMALock.3D21159A virus can do?

  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a known DMALocker ransomware decryption instruction / key file.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.DMALock.3D21159A?


File Info:

crc32: FD487542
md5: bd341d593a3086024e21cd5d73ee9ddc
name: BD341D593A3086024E21CD5D73EE9DDC.mlw
sha1: 6a9460edb11b0dcddb31c1042222ec8e83ad8421
sha256: ee0cac1e7845dbeed9594ad647b7aea1b99e0cba29b33ce70a0634f10d852e3d
sha512: d49fd669ac3f48f8a7aa152f4ef6d13f76a9c2d951f43ab97977b9671344252e1187cb966d399d9cb9f89fb24e530ead8067d0ddd723c5b9f50ec21ecf4e0107
ssdeep: 3072:OWYTNhp1KqF+Y+98dsE1HDZEtNhVEyy/:lYTPtFi9YZZghWV/
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.DMALock.3D21159A also known as:

K7AntiVirusTrojan ( 004ddcc51 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4199
CynetMalicious (score: 99)
CAT-QuickHealRansomware.DMALocker.A5
ALYacGeneric.Ransom.DMALock.3D21159A
CylanceUnsafe
ZillyaTrojan.Agent.Win32.683374
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004ddcc51 )
Cybereasonmalicious.93a308
CyrenW32/DMALocker.A.gen!Eldorado
SymantecRansom.DMALocker
ESET-NOD32a variant of Win32/Filecoder.DMALocker.C
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.DMALock.3D21159A
NANO-AntivirusTrojan.Win32.Encoder.ebpgwl
MicroWorld-eScanGeneric.Ransom.DMALock.3D21159A
TencentWin32.Trojan.Filecoder.Pgmm
Ad-AwareGeneric.Ransom.DMALock.3D21159A
SophosMal/Generic-R + Mal/DMALock-A
ComodoTrojWare.Win32.Ransom.DMALocker.A@6ayrqa
BitDefenderThetaGen:NN.ZexaF.34142.muW@aOYQyihi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MADLOCKER.SMLV
McAfee-GW-EditionGenericRXAJ-NF!BD341D593A30
FireEyeGeneric.mg.bd341d593a308602
EmsisoftGeneric.Ransom.DMALock.3D21159A (B)
JiangminTrojan.Agent.xic
AviraHEUR/AGEN.1107983
eGambitUnsafe.AI_Score_88%
Antiy-AVLTrojan/Generic.ASMalwS.17EFAC5
MicrosoftRansom:Win32/DMALocker.B
ArcabitGeneric.Ransom.DMALock.3D21159A
SUPERAntiSpywareRansom.DMALocker/Variant
GDataWin32.Trojan-Ransom.DMALocker.B
AhnLab-V3Malware/Win32.Generic.C1465743
McAfeeGenericRXAJ-NF!BD341D593A30
MAXmalware (ai score=80)
VBA32Win32.Trojan.Cryptor.Heur
MalwarebytesMalware.AI.4128023301
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_MADLOCKER.SMLV
RisingTrojan.Kryptik!1.C2FC (CLASSIC)
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.35100!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.DMALock.3D21159A?

Generic.Ransom.DMALock.3D21159A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment