Ransom

About “Generic.Ransom.DMR.CAAB9562” infection

Malware Removal

The Generic.Ransom.DMR.CAAB9562 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.DMR.CAAB9562 virus can do?

  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself

Related domains:

edgedl.me.gvt1.com
code.jquery.com
ocsp.comodoca.com
ocsp.usertrust.com
uupload.ir
update.googleapis.com

How to determine Generic.Ransom.DMR.CAAB9562?


File Info:

crc32: 1EA7860F
md5: 71fe793d62253f6e98557e7016fcdc9b
name: 71FE793D62253F6E98557E7016FCDC9B.mlw
sha1: d840fc2bc957ac29adb86e2fe1fbdc498e876835
sha256: fb638798f6b72be4ff577b31b97383d9bb3afe3f3da6648eca2db7a50251e44f
sha512: 3bcd78eb0e3b6161aad1a13e419cac794c004a8715ebd4ce544bfc21cbaed674c46a308f3cd96f8d2dedb5aab80b4a37d8dd2f49970a7cc4b8bd1e091a5ad3f4
ssdeep: 6144:K4nHSxgP5LUbPbznsSp60YWsJZBvldfRkXnjJJJGwkTUDqJZxWUX3LUoN5ms:K4negP5LUHTDYL4JwlUDwU8gC
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.DMR.CAAB9562 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGeneric.Ransom.DMR.CAAB9562
SangforTrojan.Win32.Save.a
Cybereasonmalicious.d62253
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FONIX.A
APEXMalicious
AvastWin32:Fonix-CC [Trj]
ClamAVWin.Ransomware.Fonix-9811540-0
KasperskyVHO:Trojan-Dropper.Win32.Agent.gen
BitDefenderGeneric.Ransom.DMR.CAAB9562
NANO-AntivirusTrojan.Win32.Encoder.ieplcs
MicroWorld-eScanGeneric.Ransom.DMR.CAAB9562
Ad-AwareGeneric.Ransom.DMR.CAAB9562
BitDefenderThetaGen:NN.ZexaF.34758.xmGfaaAVDZji
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.71fe793d62253f6e
EmsisoftGeneric.Ransom.DMR.CAAB9562 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.cmvv
AviraHEUR/AGEN.1141022
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/FonixCrypt.MA!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.Ransom.DMR.CAAB9562
AhnLab-V3Malware/Win.Ransom.R418630
Acronissuspicious
McAfeeGenericRXAA-AA!71FE793D6225
MAXmalware (ai score=84)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.Fonix
PandaTrj/GdSda.A
RisingRansom.Fonix!1.CA6D (CLASSIC)
IkarusTrojan-Ransom.FileCrypter
FortinetW32/FONIX.A!tr.ransom
AVGWin32:Fonix-CC [Trj]

How to remove Generic.Ransom.DMR.CAAB9562?

Generic.Ransom.DMR.CAAB9562 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment