Ransom

Generic.Ransom.PWS.Locker.DE23981B removal tips

Malware Removal

The Generic.Ransom.PWS.Locker.DE23981B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.PWS.Locker.DE23981B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.PWS.Locker.DE23981B?


File Info:

crc32: 5B639312
md5: 0373c2a1970a05d838c68e5070f53a8e
name: 0373C2A1970A05D838C68E5070F53A8E.mlw
sha1: c844938edda94fc07c0a43269f9ae10900511eba
sha256: 500db3d696ee6a26cfe2aa35f8563e5d47767ef23818c5cae130f68b638cf430
sha512: 8532f67b92fe23e249bfe8323a958fd8bfae7a84221ca1dc4c1b70af278b2906bc656fe972c0327f20bacab7bf277f975a053435aa079cea15be4c3432834cd3
ssdeep: 1536:3nt7D3TDHbBWSbwbSNzpD2nWael+RJWAaRqhNvuvUzP:3RDTD7dBiWaeoJhNm0
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.PWS.Locker.DE23981B also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.PWS.Locker.DE23981B
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
Cybereasonmalicious.1970a0
CyrenW32/Agent.CWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.abzo
BitDefenderDeepScan:Generic.Ransom.PWS.Locker.DE23981B
MicroWorld-eScanDeepScan:Generic.Ransom.PWS.Locker.DE23981B
Ad-AwareDeepScan:Generic.Ransom.PWS.Locker.DE23981B
BitDefenderThetaGen:NN.ZexaF.34142.h8Y@auvijwp
McAfee-GW-EditionBehavesLike.Win32.Ransomware.cm
FireEyeGeneric.mg.0373c2a1970a05d8
EmsisoftDeepScan:Generic.Ransom.PWS.Locker.DE23981B (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1142906
eGambitUnsafe.AI_Score_65%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataDeepScan:Generic.Ransom.PWS.Locker.DE23981B
AhnLab-V3Malware/Win32.RL_Generic.R361916
McAfeeArtemis!0373C2A1970A
MAXmalware (ai score=82)
VBA32BScope.TrojanRansom.Agent
MalwarebytesRansom.CryCipher
IkarusTrojan.Win32.Meterpreter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Locker.CD6F!tr.ransom
AVGWin32:Malware-gen

How to remove Generic.Ransom.PWS.Locker.DE23981B?

Generic.Ransom.PWS.Locker.DE23981B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment