Ransom

Generic.Ransom.DMALock.E1B7FFD4 malicious file

Malware Removal

The Generic.Ransom.DMALock.E1B7FFD4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.DMALock.E1B7FFD4 virus can do?

  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a known DMALocker ransomware decryption instruction / key file.

How to determine Generic.Ransom.DMALock.E1B7FFD4?


File Info:

crc32: 38A0B4D6
md5: 3a079c3d39f162680eaa566a309c1375
name: 3A079C3D39F162680EAA566A309C1375.mlw
sha1: e1f2514f820b4cb1b70cc753d221c2b9bc732390
sha256: 3c40ea312d5408378dedda61dfc395c851bf7d82fcd20746db9e2bb2ebdf381a
sha512: 8a4d422ead69252e844ab745845aea7676238b1dd50e42efaaf15452dff6e35b8b7fbac4cc801717b16b7b1a836bcf87cf6bf548c9b82c8757594db5a8631f5a
ssdeep: 1536:xUd4wyIMrH68iWq3QTRD9698x0h0DPZskjLbNCKpJFpKzLeUCoOvhVjwh:xA4w1MrH6PLQRFpjltJFUWUCPvhVjw
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.DMALock.E1B7FFD4 also known as:

K7AntiVirusTrojan ( 004f04f21 )
LionicTrojan.Win32.Agent.mCYi
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4199
CynetMalicious (score: 99)
CAT-QuickHealRansomware.DMALocker.A5
ALYacGeneric.Ransom.DMALock.E1B7FFD4
CylanceUnsafe
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004f04f21 )
Cybereasonmalicious.d39f16
CyrenW32/DMALocker.A.gen!Eldorado
SymantecRansom.DMALocker
ESET-NOD32a variant of Win32/Filecoder.DMALocker.C
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.DMALock.E1B7FFD4
NANO-AntivirusTrojan.Win32.Encoder.eercru
MicroWorld-eScanGeneric.Ransom.DMALock.E1B7FFD4
TencentMalware.Win32.Gencirc.114ba7d4
Ad-AwareGeneric.Ransom.DMALock.E1B7FFD4
SophosML/PE-A + Mal/DMALock-A
ComodoTrojWare.Win32.Ransom.DMALocker.A@6ayrqa
BitDefenderThetaGen:NN.ZexaF.34170.muW@aubosWbi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MADLOCKER.SMLV
McAfee-GW-EditionBehavesLike.Win32.Downloader.dt
FireEyeGeneric.mg.3a079c3d39f16268
EmsisoftGeneric.Ransom.DMALock.E1B7FFD4 (B)
JiangminTrojan.Agent.aglb
WebrootW32.Ransom.Dmalocker
AviraHEUR/AGEN.1107983
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.19DFAD4
MicrosoftRansom:Win32/DMALocker.B
ArcabitGeneric.Ransom.DMALock.E1B7FFD4
SUPERAntiSpywareRansom.DMALocker/Variant
GDataWin32.Trojan-Ransom.DMALocker.B
AhnLab-V3Trojan/Win.Generic.R442600
McAfeeGenericRXAJ-NF!3A079C3D39F1
MAXmalware (ai score=89)
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.4128023301
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_MADLOCKER.SMLV
RisingTrojan.Kryptik!1.C2FC (CLASSIC)
YandexTrojan.GenAsa!+1eitmnfFuQ
IkarusTrojan.Win32.Filecoder
FortinetW32/Kryptik.35100!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.DMALock.E1B7FFD4?

Generic.Ransom.DMALock.E1B7FFD4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment