Ransom

Generic.Ransom.MBRLock.E4FC68F6 removal instruction

Malware Removal

The Generic.Ransom.MBRLock.E4FC68F6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.MBRLock.E4FC68F6 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempted to write directly to a physical drive

How to determine Generic.Ransom.MBRLock.E4FC68F6?


File Info:

name: E03FEB4189C652327D60.mlw
path: /opt/CAPEv2/storage/binaries/49516402e63e8777e07b305450fd69927ee7f767c19ba2d966abef5ad4c3afa6
crc32: A51ECDDF
md5: e03feb4189c652327d60064b888fc705
sha1: e161ef85cf6cfcc1b7156e17282864fc7e87fb02
sha256: 49516402e63e8777e07b305450fd69927ee7f767c19ba2d966abef5ad4c3afa6
sha512: 4725022456840fca0754b4da4f68cfb91cdd8e9fa25076f3bf87a27f2002fe1c1bdcad1ade6109aefa798c045b5c6cc1a7f3bc85c92be1bdbfc91a3dfd47828c
ssdeep: 24576:uXKUvFniqqcHxSzWJ1TZaqdiXSp0c02uFG6dAk3HMgc4qv:uXRv7qcASJ1TZaqdwk0c05HGiNcJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A285D0F2F59281FEC6201930096AE7F6DAF96E066B14CA8357D4FD5F3872D80A533129
sha3_384: 79b6b5346c9b79c246fbe35b5364db4cb7d60974155e0bf3f67c76cd7c43ec8ac50d1eb92950382fd22e22abdec8754f
ep_bytes: 558bec6aff6888a857006844da460064
timestamp: 2022-08-30 08:47:34

Version Info:

0: [No Data]

Generic.Ransom.MBRLock.E4FC68F6 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanDeepScan:Generic.Ransom.MBRLock.E4FC68F6
ClamAVWin.Trojan.Flystudio-9943951-0
FireEyeGeneric.mg.e03feb4189c65232
ALYacDeepScan:Generic.Ransom.MBRLock.E4FC68F6
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWAdware ( 004b87ea1 )
Cybereasonmalicious.189c65
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/MBRlock.AQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Mbro.gen
BitDefenderDeepScan:Generic.Ransom.MBRLock.E4FC68F6
AvastWin32:RansomX-gen [Ransom]
TencentTrojan.Win32.Foreign.16000100
Ad-AwareDeepScan:Generic.Ransom.MBRLock.E4FC68F6
EmsisoftDeepScan:Generic.Ransom.MBRLock.E4FC68F6 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
DrWebTrojan.MulDrop20.48912
VIPREDeepScan:Generic.Ransom.MBRLock.E4FC68F6
TrendMicroRansom_Mbro.R011C0GI122
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11UD6H7
AviraTR/Ransom.MBRlock.vfmhd
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitDeepScan:Generic.Ransom.MBRLock.E4FC68F6
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C4335005
McAfeeArtemis!E03FEB4189C6
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallRansom_Mbro.R011C0GI122
RisingRansom.MBRLock!1.D7C5 (CLASSIC)
YandexTrojan.GenAsa!aJ6jK3uE76k
IkarusTrojan.Win32.MBRlock
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/MBRlock.AQ!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34606.RrW@aSit95pb
AVGWin32:RansomX-gen [Ransom]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Generic.Ransom.MBRLock.E4FC68F6?

Generic.Ransom.MBRLock.E4FC68F6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment