Ransom

What is “Generic.Ransom.Unlock92.F2DBBA4A”?

Malware Removal

The Generic.Ransom.Unlock92.F2DBBA4A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Unlock92.F2DBBA4A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Unlock92.F2DBBA4A?


File Info:

crc32: CC944C78
md5: 1025f9140240dd23170996d0e7f9e22f
name: 1025F9140240DD23170996D0E7F9E22F.mlw
sha1: f8ef9a1a3635511eb492a873d42965f9baf7312d
sha256: b5ef97e05ebd8a2bb10909040e71a213ca8ceba44f405bac5a372c83a613a859
sha512: 700594f86c0223a05490e59d1c5da65839bbcc52dcb3a93420f84995a4139ab5727e735914b68523be8ca887b26ee55b99604459c4fe7c87b96bfd30513c8c6c
ssdeep: 3072:DhcHyAQZanwIG2PTn4N2b4HuwIAjfL1IfP+sNeeTGWAr0EmfnZxegsRXXX:1cHyTanwIG2PTn4N2b4HuwIAjfL1IfP
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Unlock92.F2DBBA4A also known as:

K7AntiVirusTrojan ( 004f5ef21 )
LionicTrojan.Win32.Deshacop.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5650
ALYacGeneric.Ransom.Unlock92.F2DBBA4A
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.3751
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Deshacop.5aa86e23
K7GWTrojan ( 004f5ef21 )
Cybereasonmalicious.40240d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.CA
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Deshacop.cxq
BitDefenderGeneric.Ransom.Unlock92.F2DBBA4A
NANO-AntivirusTrojan.Win32.Deshacop.eimtet
MicroWorld-eScanGeneric.Ransom.Unlock92.F2DBBA4A
TencentWin32.Trojan.Deshacop.Dtsn
Ad-AwareGeneric.Ransom.Unlock92.F2DBBA4A
BitDefenderThetaGen:NN.ZemsilF.34170.hqW@aGPuV8hk
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R034E02AJ17
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.1025f9140240dd23
EmsisoftGeneric.Ransom.Unlock92.F2DBBA4A (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Deshacop.sd
Antiy-AVLTrojan/Generic.ASMalwS.1AAA73F
KingsoftWin32.Troj.Deshacop.c.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
ArcabitGeneric.Ransom.Unlock92.F2DBBA4A
GDataMSIL.Trojan-Ransom.Unlock92.A
McAfeeArtemis!1025F9140240
MAXmalware (ai score=86)
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R034E02AJ17
YandexTrojan.Deshacop!NVB7WTHdAnI
IkarusTrojan.MSIL.Filecoder
FortinetMSIL/Filecoder.CA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Unlock92.F2DBBA4A?

Generic.Ransom.Unlock92.F2DBBA4A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment