Ransom

Generic.Ransom.MBRLock.F2B5BE13 information

Malware Removal

The Generic.Ransom.MBRLock.F2B5BE13 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.MBRLock.F2B5BE13 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Adds a new user to the system
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the XiaoBa malware family
  • Adds a new user to the Administrators group
  • Overwrites local Administrator password
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.MBRLock.F2B5BE13?


File Info:

name: 58DFA448E34466B4FD13.mlw
path: /opt/CAPEv2/storage/binaries/8256494bdbe1cc9502c5c39e91cd709535b6b14f9d3d4d2580c5ac753832fd0d
crc32: 0C348345
md5: 58dfa448e34466b4fd13f15aec268ab4
sha1: 31623beaa309cd59ca3ada8ff2f562be44c1f2fd
sha256: 8256494bdbe1cc9502c5c39e91cd709535b6b14f9d3d4d2580c5ac753832fd0d
sha512: f5ca9dae40e33e2812004379cc4e5a4b21fd6e693fc02671e82f0c9c271e8e7f512f3788717fa13f22935d12cfa8cb2f02b3cd2fd056f968a3016b4135ef1a1e
ssdeep: 12288:9l/Vdz2I37w/+oZbjT3KPrTjHgTY1L5ftfsUGkpuaV+Vx:9XdZLwGoZT36PDCZkpuaVux
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165257B82B68288B2D53317F04076EB369622AE455B35DAC353F8FC2AFDB31815F27195
sha3_384: aa8fad6cf135dd1f4402ee9c4a98c51df913018173c264fa95f279447dee4ae5f632a27b0855ef27b85ef52aa857b76c
ep_bytes: 558bec6aff6808754b0068d4ce470064
timestamp: 2022-10-03 11:18:40

Version Info:

0: [No Data]

Generic.Ransom.MBRLock.F2B5BE13 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Ransom.MBRLock.F2B5BE13
FireEyeGeneric.mg.58dfa448e34466b4
McAfeeArtemis!58DFA448E344
CylanceUnsafe
VIPREGeneric.Ransom.MBRLock.F2B5BE13
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.8e3446
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/LockScreen.BHZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.KillMBR.gen
BitDefenderGeneric.Ransom.MBRLock.F2B5BE13
AvastWin32:Trojan-gen
TencentTrojan.Win32.Foreign.16000100
Ad-AwareGeneric.Ransom.MBRLock.F2B5BE13
EmsisoftGeneric.Ransom.MBRLock.F2B5BE13 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
TrendMicroRansom.Win32.MBRLOCKER.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Ransom.fptng
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftRansom:Win32/Genasom.ID
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.11UD6H7
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.34698.8qW@aqmZOKhb
ALYacGeneric.Ransom.MBRLock.F2B5BE13
MAXmalware (ai score=88)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallRansom.Win32.MBRLOCKER.SM
RisingRansom.MBRLock!1.B6DC (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/MBRlock.AQ!tr.ransom
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Generic.Ransom.MBRLock.F2B5BE13?

Generic.Ransom.MBRLock.F2B5BE13 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment