Ransom

Generic.Ransom.DMALock.722EBE2B removal

Malware Removal

The Generic.Ransom.DMALock.722EBE2B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.DMALock.722EBE2B virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Exhibits behavior characteristic of DMALocker ransomware
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a known DMALocker ransomware decryption instruction / key file.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.DMALock.722EBE2B?


File Info:

crc32: 5884073A
md5: eab3eced289325afe999b5a22c58a010
name: EAB3ECED289325AFE999B5A22C58A010.mlw
sha1: 2bc04710a94bfb6cb7bd386a66797181f4d99fab
sha256: cbb0b327c51157fa12b898b46c0ea3cd0f8aaef781675aed95985a3e86778448
sha512: 7202ab451b054c20078ed99923e1e1d5f47b28baa47e60eff3cb15d066ba4cc008743aba8c53e841f604841c74f6f0c1610f9db860c5d497347fe8c98c604b89
ssdeep: 1536:faVfjZq3zMmmcK8x8XP4Ik9hC9wPHxyrv1bfk/UNC3hSm77aN3XJRvVpRKISXR:iVflqwmzx3CmH4T1bgUNyh
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.DMALock.722EBE2B also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4199
CynetMalicious (score: 99)
CAT-QuickHealWorm.Gamarue.28904
ALYacGeneric.Ransom.DMALock.722EBE2B
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Blocker.839929e6
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.d28932
CyrenW32/DMALocker.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.DMALocker.B
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.iame
BitDefenderGeneric.Ransom.DMALock.722EBE2B
NANO-AntivirusTrojan.Win32.Drop.dzyiag
ViRobotTrojan.Win32.Ransom.377376
MicroWorld-eScanGeneric.Ransom.DMALock.722EBE2B
TencentMalware.Win32.Gencirc.114c2bf2
Ad-AwareGeneric.Ransom.DMALock.722EBE2B
SophosMal/Generic-S
ComodoMalware@#1yn1j54bvs74d
BitDefenderThetaGen:NN.ZexaF.34170.xuX@aGmEmZbi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MADLOCKER.SMLV
McAfee-GW-EditionRansomware-FDF!EAB3ECED2893
FireEyeGeneric.mg.eab3eced289325af
EmsisoftGeneric.Ransom.DMALock.722EBE2B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.bhc
WebrootW32.Downloader.Gen
AviraTR/Taranis.2195
Antiy-AVLTrojan/Generic.ASMalwS.16DEBB6
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/DMALocker
GDataWin32.Trojan-Ransom.DMALocker.A
AhnLab-V3Trojan/Win32.DMALocker.C1324619
McAfeeRansomware-FDF!EAB3ECED2893
MAXmalware (ai score=82)
VBA32BScope.TrojanRansom.Blocker
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_MADLOCKER.SMLV
RisingTrojan.Kryptik!1.C2FC (CLASSIC)
YandexTrojan.GenAsa!58zsJz1qKUU
IkarusTrojan.Win32.Filecoder
FortinetW32/Filecoder.30120!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.DMALock.722EBE2B?

Generic.Ransom.DMALock.722EBE2B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment