Ransom

About “Generic.Ransom.DMALock.B6E95227” infection

Malware Removal

The Generic.Ransom.DMALock.B6E95227 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.DMALock.B6E95227 virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Exhibits behavior characteristic of DMALocker ransomware
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Creates a known DMALocker ransomware decryption instruction / key file.
  • Anomalous binary characteristics

How to determine Generic.Ransom.DMALock.B6E95227?


File Info:

crc32: C5ED88D5
md5: e70df6b85dedc428f516f464fa50dd76
name: E70DF6B85DEDC428F516F464FA50DD76.mlw
sha1: f4bba20ace756e9bb8c32a8ba345cf9a722eef47
sha256: c96d5089d72e17b1236b667a5cc2b144b1ef741fdba45328ed28039f95bad03f
sha512: da9b363b754799b3eeaa998dd3c9441629866c23b462c0c4178743512f58d4b5bddd082d5b77ef863195d02f100e15aa19d3aa68e3913e45e7ea4f900bb190d5
ssdeep: 1536:CA0JEPpCrbBPUrOPDMq/swEUR3nBf/tmekK5LYFhisBN:CwPqbjMjw33Bf/tmU5L6hisBN
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.DMALock.B6E95227 also known as:

K7AntiVirusTrojan ( 004dcfbb1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3935
CynetMalicious (score: 99)
CAT-QuickHealRansom.DMALocker.A5
ALYacGeneric.Ransom.DMALock.B6E95227
CylanceUnsafe
ZillyaTrojan.DMALocker.Win32.2
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.6e4fbd60
K7GWTrojan ( 004dcfbb1 )
Cybereasonmalicious.85dedc
CyrenW32/DMALocker.A.gen!Eldorado
SymantecRansom.DMALocker
ESET-NOD32Win32/Filecoder.DMALocker.B
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.iaky
BitDefenderGeneric.Ransom.DMALock.B6E95227
NANO-AntivirusTrojan.Win32.Drop.dzxjzw
ViRobotTrojan.Win32.Ransom.98848
MicroWorld-eScanGeneric.Ransom.DMALock.B6E95227
TencentMalware.Win32.Gencirc.114c1d75
Ad-AwareGeneric.Ransom.DMALock.B6E95227
SophosMal/Generic-S
ComodoMalware@#2w59hntqor83e
BitDefenderThetaAI:Packer.49BD23B81F
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MADLOCKER.SMLV
McAfee-GW-EditionGenericRXFV-IX!E70DF6B85DED
FireEyeGeneric.mg.e70df6b85dedc428
EmsisoftGeneric.Ransom.DMALock.B6E95227 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.bhc
WebrootW32.Gen.BT
AviraTR/Taranis.2195
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.16C1549
MicrosoftRansom:Win32/DMALocker
ArcabitGeneric.Ransom.DMALock.B6E95227
SUPERAntiSpywareRansom.DMALocker/Variant
GDataWin32.Trojan-Ransom.DMALocker.A
TACHYONTrojan/W32.Blocker.98848
AhnLab-V3Trojan/Win32.DMALocker.R173933
McAfeeGenericRXFV-IX!E70DF6B85DED
MAXmalware (ai score=87)
VBA32Hoax.Blocker
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_MADLOCKER.SMLV
RisingTrojan.Kryptik!1.C2FC (CLASSIC)
YandexTrojan.Blocker!NN0qKgqL3n0
IkarusTrojan.Win32.Filecoder
FortinetW32/Filecoder.30120!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.DMALock.B6E95227?

Generic.Ransom.DMALock.B6E95227 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment