Ransom

Generic.Ransom.Unlock92.F5EE68B1 removal tips

Malware Removal

The Generic.Ransom.Unlock92.F5EE68B1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Unlock92.F5EE68B1 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Unlock92.F5EE68B1?


File Info:

crc32: 10996B10
md5: 5a49852ae3b31940dc8f5bd617c68471
name: 5A49852AE3B31940DC8F5BD617C68471.mlw
sha1: c74f5ee30d85e9fd50a935c492b43dbd23cf0467
sha256: 751d9a9d07b9453b741c09119d1e796f68d47fb6b0d08a2fc7facb8b7c083f19
sha512: ca06336d7e49c16fcba5d6e386a181375b62bc0440c75f83208b7c3c1b512f61ce64538e15f856775d609384d95f8ed275fe005ea7b28495bcc0b28e8a9851c6
ssdeep: 1536:R0HGHXcUOkXcKLIAPBQcLocyjyB6t6d9Zeyf9OHmwt:R0mHXcsMKLIAPBQcxIyBrd9cyfbwt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Unlock92.F5EE68B1 also known as:

K7AntiVirusTrojan ( 004f84891 )
DrWebTrojan.Encoder.6140
CynetMalicious (score: 85)
ALYacTrojan.Ransom.Unlock92
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.726
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:MSIL/Filecoder.1644ba2f
K7GWTrojan ( 004f84891 )
Cybereasonmalicious.ae3b31
SymantecRansom.Cerber
ESET-NOD32a variant of MSIL/Filecoder.CL
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.Unlock92.F5EE68B1
NANO-AntivirusTrojan.Win32.Deshacop.egrfwb
MicroWorld-eScanGeneric.Ransom.Unlock92.F5EE68B1
TencentWin32.Trojan.Deshacop.Swbh
Ad-AwareGeneric.Ransom.Unlock92.F5EE68B1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34670.fqW@aK9O45kk
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPZXAS.C
McAfee-GW-EditionGeneric.akn
FireEyeGeneric.mg.5a49852ae3b31940
EmsisoftGeneric.Ransom.Unlock92.F5EE68B1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Deshacop.sj
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1116609
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Troj.Deshacop.c.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
AegisLabTrojan.Win32.Deshacop.4!c
GDataMSIL.Trojan-Ransom.Unlock92.C
AhnLab-V3Trojan/Win32.Geograph.C1575875
McAfeeGeneric.akn
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYPZXAS.C
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.Deshacop!v9U1HD/58VA
IkarusTrojan.MSIL.Filecoder
FortinetMSIL/Filecoder.CL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Unlock92.HwMA2P8A

How to remove Generic.Ransom.Unlock92.F5EE68B1?

Generic.Ransom.Unlock92.F5EE68B1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment