Ransom

Generic.Ransom.DMALock.5A544590 (file analysis)

Malware Removal

The Generic.Ransom.DMALock.5A544590 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.DMALock.5A544590 virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Exhibits behavior characteristic of DMALocker ransomware
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a known DMALocker ransomware decryption instruction / key file.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.DMALock.5A544590?


File Info:

crc32: 7D4DB744
md5: 4190df2af81ece296c465e245fc0caea
name: 4190DF2AF81ECE296C465E245FC0CAEA.mlw
sha1: 2928889b268f8dfde9db94d54de39e217c4cc337
sha256: 8abca2cf6e2672ca406b5bdb150b14c345866281b670ae1389cc5cbeac55c8e6
sha512: dd116b4d8dd076eef2bcf7df0110c55409a8b63bf88236357bd2abe2d835b34ce6f0ca379738750d35386f8cb31fda41618c8790c66026ac6b27f95dd4f80f1b
ssdeep: 1536:fABJEPpCrbBPUrOPDMq/swEUR3nBf/tmekKILPthisY:fpPqbjMjw33Bf/tmUILlhisY
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.DMALock.5A544590 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004dcfbb1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3935
CynetMalicious (score: 99)
CAT-QuickHealRansom.DMALocker.A5
McAfeeGenericRXFV-IX!4190DF2AF81E
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.33204
SangforTrojan.Win32.Taranis.2195
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.375349ae
K7GWTrojan ( 004dcfbb1 )
Cybereasonmalicious.af81ec
CyrenW32/DMALocker.A.gen!Eldorado
SymantecRansom.DMALocker
ESET-NOD32a variant of Win32/Filecoder.DMALocker.B
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.iamg
BitDefenderGeneric.Ransom.DMALock.5A544590
NANO-AntivirusTrojan.Win32.Drop.dzvrad
ViRobotTrojan.Win32.Z.Blocker.98848.C
SUPERAntiSpywareRansom.DMALocker/Variant
MicroWorld-eScanGeneric.Ransom.DMALock.5A544590
TencentMalware.Win32.Gencirc.114c2309
Ad-AwareGeneric.Ransom.DMALock.5A544590
SophosMal/Generic-R + Troj/DMALockr-A
ComodoMalware@#1ac8kgcdx3sjl
BitDefenderThetaGen:NN.ZexaF.34692.guX@aSb0Vedi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MADLOCKER.SMLV
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.4190df2af81ece29
EmsisoftGeneric.Ransom.DMALock.5A544590 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.bhc
WebrootRansom.Dmalocker
AviraTR/Taranis.2195
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.16C1549
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/DMALocker
AegisLabTrojan.Win32.Agent.mCYi
ZoneAlarmTrojan-Ransom.Win32.Blocker.iamg
GDataWin32.Trojan-Ransom.DMALocker.A
TACHYONTrojan/W32.Blocker.98848
AhnLab-V3Trojan/Win32.DMALocker.R173933
VBA32Hoax.Blocker
MAXmalware (ai score=100)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_MADLOCKER.SMLV
RisingTrojan.Kryptik!1.C2FC (CLASSIC)
YandexTrojan.Blocker!Pzs+ijySV5g
IkarusTrojan.Win32.Filecoder
FortinetW32/Blocker.B!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.DMALock.5A544590?

Generic.Ransom.DMALock.5A544590 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment