Ransom

How to remove “Generic.Ransom.MBRLock.61E84A94”?

Malware Removal

The Generic.Ransom.MBRLock.61E84A94 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.MBRLock.61E84A94 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Likely installs a bootkit via raw harddisk modifications
  • Network activity detected but not expressed in API logs

How to determine Generic.Ransom.MBRLock.61E84A94?


File Info:

crc32: 9A1FC833
md5: 22e6dcfe2e14b98885aac6dcd67bfaf1
name: 22E6DCFE2E14B98885AAC6DCD67BFAF1.mlw
sha1: 1681042fd860d66fc1d8addbdf733c3aa4b200cc
sha256: 62db891892a39a96732f474c6b12fbc68d954c7e3b48f28f4d18bf15bb0bc42e
sha512: afcb4e2e6bd2512ed9b9a58a38e98575210dfe1e70995aaa21620f1aa6a3f5b02dfc199068ab4f3cafcbb78e4df45e40eb446a547e37de94bf29ee622f045472
ssdeep: 12288:5JJ7/8hukd5+nUd8bqr6ieOXqO1lk8MObHQbyDYc:5JJ7wFd5WUd9u3OXqOXkHObHQb0Yc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x83b7x53d6x66f4x591ax8f85x52a9x52a0x4f5cx8005QQxff1a3060313757
FileVersion: 2.3.1.2
CompanyName: QQxff1a3060313757
Comments: 2.3.1.2x7248x672c
ProductName: x5c0fx96e8x521bx4e16x5175x9b42x8f85x52a9
ProductVersion: 2.3.1.2
FileDescription: x900fx89c6x63cfx8fb9xff0cx65b9x6846x81eax7784xff01
Translation: 0x0804 0x04b0

Generic.Ransom.MBRLock.61E84A94 also known as:

K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericRI.S18564192
ALYacGeneric.Ransom.MBRLock.61E84A94
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.55764
SangforWin.Malware.Zusy-6840460-0
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.e2e14b
CyrenW32/S-1885075c!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MBRlock.AQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan-Ransom.Win32.Foreign.naew
BitDefenderGeneric.Ransom.MBRLock.61E84A94
NANO-AntivirusTrojan.Win32.RiskGen.eluqfb
MicroWorld-eScanGeneric.Ransom.MBRLock.61E84A94
TencentWin32.Trojan.Foreign.Hrza
Ad-AwareGeneric.Ransom.MBRLock.61E84A94
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34790.Vq0@auJwSbjb
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.MBRLOCKER.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
FireEyeGeneric.mg.22e6dcfe2e14b988
EmsisoftGeneric.Ransom.MBRLock.61E84A94 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blamon.aah
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FA
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Molock!rfn
AegisLabTrojan.Win32.Generic.mqYD
GDataWin32.Trojan.PSE.19Q2126
Acronissuspicious
McAfeeArtemis!22E6DCFE2E14
MAXmalware (ai score=89)
VBA32Trojan-Ransom.Foreign
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.MBRLOCKER.SM
RisingRansom.MBRlock!1.B6DC (CLASSIC)
YandexTrojan.GenAsa!3nrLpeEQWWY
IkarusTrojan.Win32.MBRlock
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/MBRlock.AQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Foreign.HgIASS8A

How to remove Generic.Ransom.MBRLock.61E84A94?

Generic.Ransom.MBRLock.61E84A94 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment