Ransom

Generic.Ransom.Unlock92.8DDF8577 removal

Malware Removal

The Generic.Ransom.Unlock92.8DDF8577 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Unlock92.8DDF8577 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.Unlock92.8DDF8577?


File Info:

crc32: 32490D03
md5: 992762d716779f2b1881edf31b6d8f72
name: 992762D716779F2B1881EDF31B6D8F72.mlw
sha1: e35f21a9b5765c01b47b4b4a1c41ab280fd0928f
sha256: 1141001ccbf8fd57a4695867088fa23fd6fb032bf28105b7a6f31cc5ff78190c
sha512: 97d634265eb89d2a921196579614f216d6bdd15145a2800d6659d909dfc2253966866349fc8f3b2eafad6aa3010d0e9fd5b55602709c9f0450c2966f2a717bf0
ssdeep: 1536:R5ubL/s/Jm307IDTFilCzZKJECkg5lEk:RobLR307IDJiEZKJpk2
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Unlock92.8DDF8577 also known as:

K7AntiVirusTrojan ( 004f574c1 )
LionicTrojan.Win32.Deshacop.4!c
DrWebTrojan.Encoder.5222
ALYacGeneric.Ransom.Unlock92.8DDF8577
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.731
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Deshacop.a2ffc057
K7GWTrojan ( 004f574c1 )
Cybereasonmalicious.716779
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.BZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Deshacop.cwy
BitDefenderGeneric.Ransom.Unlock92.8DDF8577
NANO-AntivirusTrojan.Win32.Encoder.efpnbh
MicroWorld-eScanGeneric.Ransom.Unlock92.8DDF8577
TencentWin32.Trojan.Deshacop.Hssd
Ad-AwareGeneric.Ransom.Unlock92.8DDF8577
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34142.euW@aqIBxVok
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic.arl
FireEyeGeneric.mg.992762d716779f2b
EmsisoftGeneric.Ransom.Unlock92.8DDF8577 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Deshacop.rn
eGambitUnsafe.AI_Score_91%
MicrosoftTrojan:Win32/Dynamer!ac
GDataGeneric.Ransom.Unlock92.8DDF8577
AhnLab-V3Trojan/Win32.Deshacop.C2406019
McAfeeRDN/Generic.arl
MAXmalware (ai score=87)
VBA32Trojan.Deshacop
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/GdSda.A
YandexTrojan.GenAsa!DuFYSmPRJbM
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.1728101.susgen
FortinetMSIL/Filecoder.BZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Unlock92.8DDF8577?

Generic.Ransom.Unlock92.8DDF8577 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment