Ransom

Generic.Ransom.DMALock.980D69A1 removal tips

Malware Removal

The Generic.Ransom.DMALock.980D69A1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.DMALock.980D69A1 virus can do?

  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a known DMALocker ransomware decryption instruction / key file.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.DMALock.980D69A1?


File Info:

crc32: 23D60657
md5: 30324660add5a5da3f3be651e8d12415
name: 30324660ADD5A5DA3F3BE651E8D12415.mlw
sha1: 6c22875171a993b7da3ece63e502f77dcb2cdc94
sha256: 10005787953872394f197f7058b7f0ba9cb4bad7cf24bbe59bbc20b7b68b531f
sha512: b93640e405fddf00ed3ffd2a6090abdb0a9a15f4457a8193b3d6e51340c66e390eb61b0f1964256a579cb257ea7ab5052c005dbe072695fadd4039e5b202d978
ssdeep: 1536:XQfKc03J+NiWq3Q/Rb9JPNhTLY5hNmkT0aNCKT9SBKnL9qCorhVTDr:XoKc03J+gLQRwvTvv9SMBqCKhVTD
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.DMALock.980D69A1 also known as:

K7AntiVirusTrojan ( 004f04f21 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4199
CAT-QuickHealRansomware.DMALocker.A5
ALYacTrojan.Ransom.DMALocker
CylanceUnsafe
ZillyaTrojan.Agent.Win32.716210
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali1001008
K7GWTrojan ( 004f04f21 )
Cybereasonmalicious.0add5a
CyrenW32/DMALocker.A.gen!Eldorado
SymantecRansom.DMALocker
ESET-NOD32a variant of Win32/Filecoder.DMALocker.C
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.DMALock.980D69A1
NANO-AntivirusTrojan.Win32.Agent.egnckh
MicroWorld-eScanGeneric.Ransom.DMALock.980D69A1
TencentWin32.Trojan.Filecoder.Lfzm
Ad-AwareGeneric.Ransom.DMALock.980D69A1
SophosMal/Generic-R + Mal/DMALock-A
ComodoTrojWare.Win32.Ransom.DMALocker.C@74luok
BitDefenderThetaGen:NN.ZexaF.34796.nuW@aq3iYani
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MADLOCKER.SMLV
McAfee-GW-EditionGenericRXAJ-NF!30324660ADD5
FireEyeGeneric.mg.30324660add5a5da
EmsisoftGeneric.Ransom.DMALock.980D69A1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agent.ajml
WebrootTrojan.Ransom.Dmalocker.A
AviraHEUR/AGEN.1107991
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/DMALocker
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.DMALocker.B
AhnLab-V3Malware/Win32.Generic.C1465743
McAfeeGenericRXAJ-NF!30324660ADD5
MAXmalware (ai score=100)
VBA32Win32.Trojan.Cryptor.Heur
MalwarebytesMalware.AI.4128023301
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_MADLOCKER.SMLV
RisingTrojan.Kryptik!1.C2FC (CLASSIC)
YandexTrojan.GenAsa!+1eitmnfFuQ
IkarusTrojan.Win32.Filecoder
FortinetW32/Kryptik.35100!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwoCOysA

How to remove Generic.Ransom.DMALock.980D69A1?

Generic.Ransom.DMALock.980D69A1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment