Ransom

Generic.Ransom.MBRLock.3DA2C162 malicious file

Malware Removal

The Generic.Ransom.MBRLock.3DA2C162 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.MBRLock.3DA2C162 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs

How to determine Generic.Ransom.MBRLock.3DA2C162?


File Info:

crc32: 33DC0F12
md5: ef29a4a80410df1b9e1dcfcbeeb71ab0
name: EF29A4A80410DF1B9E1DCFCBEEB71AB0.mlw
sha1: ef1d44f58ac757b30656e24b454d9781561556df
sha256: 43610ffffa2ab882699ae651d8616d0637821c59f553c7e0a16c59391356db45
sha512: baff45466157aa6a317a0021d6f20e87dea1240c3b04ee446bcef6012df288d13358d2b1d62009e92ffa21bd5643bbf9e9b79cba1090d95889efe6095d6b760b
ssdeep: 12288:s+UndCwyGHVGZLe3/okv6sXLTrPoSQhajOCMW0RxQt3Eqv:KdCwpY1m/okv6sXfryhajVR0RxQt3Eq
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: www.99hei.com
FileVersion: 1.0.0.0
CompanyName:
Comments: www.99hei.com
ProductName: www.99hei.com
ProductVersion: 1.0.0.0
FileDescription: www.99hei.com
Translation: 0x0804 0x04b0

Generic.Ransom.MBRLock.3DA2C162 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f6c891 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Wsgame.51180
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5251179
ALYacGeneric.Ransom.MBRLock.3DA2C162
CylanceUnsafe
SangforRansom.Win32.Foreign.nbtp
AlibabaRansom:Win32/Foreign.31e44c04
K7GWTrojan ( 004f6c891 )
Cybereasonmalicious.80410d
CyrenW32/S-776111c5!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/MBRlock.AQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.nbtp
BitDefenderGeneric.Ransom.MBRLock.3DA2C162
NANO-AntivirusTrojan.Win32.Agent.ecvuvb
MicroWorld-eScanGeneric.Ransom.MBRLock.3DA2C162
TencentWin32.Trojan.Foreign.Alsj
Ad-AwareGeneric.Ransom.MBRLock.3DA2C162
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34790.HmKfa0M6t3ob
TrendMicroRansom.Win32.MBRLOCKER.SM
McAfee-GW-EditionGenericRXES-GN!29FF912AC6F8
FireEyeGeneric.mg.ef29a4a80410df1b
EmsisoftGeneric.Ransom.MBRLock.3DA2C162 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.awx
WebrootW32.Malware.gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitGeneric.Ransom.MBRLock.3DA2C162
ZoneAlarmTrojan-Ransom.Win32.Foreign.nbtp
GDataWin32.Trojan-Ransom.Molock.A
Acronissuspicious
McAfeeArtemis!EF29A4A80410
MAXmalware (ai score=88)
VBA32SScope.Trojan.PWS.22627
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallRansom.Win32.MBRLOCKER.SM
RisingRansom.MBRlock!1.B6DC (CLASSIC)
YandexTrojan.GenAsa!ybv8ECUyKWQ
IkarusTrojan.Win32.MBRlock
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/MBRlock.AQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Molock.HxIBEpsA

How to remove Generic.Ransom.MBRLock.3DA2C162?

Generic.Ransom.MBRLock.3DA2C162 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment