Ransom

Ransom.MBRLock.3 removal

Malware Removal

The Ransom.MBRLock.3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.MBRLock.3 virus can do?

  • Starts servers listening on 0.0.0.0:19730
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Ransom.MBRLock.3?


File Info:

crc32: 95AB3942
md5: b1816673c78965a2febf7e7018340c18
name: B1816673C78965A2FEBF7E7018340C18.mlw
sha1: 01cc158f347044cb40aafb2417c01c817b8fe236
sha256: e16d5797d519fdee40d1df1002813f401ac113ccefd0864b2f83f5c65c40c764
sha512: 87e0af4243feaf2d82c692f72be273582af7cbf70b8e45ef1619aff221291fe6da3939b0afa82794b3ca8104eb675494f963c23846be3b170aed42ae02c5467c
ssdeep: 24576:NI9/0+iCV6gNNuSg+Az2f/MhzmTZiUytwzlmD4:NI9/4UNuU1/8zmI5D4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x672cx6e90x7801x6765x81eawww.xiaodao.la
FileVersion: 1.0.0.0
CompanyName: x672cx6e90x7801x6765x81eawww.xiaodao.la
Comments: x672cx6e90x7801x6765x81eawww.xiaodao.la
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x672cx6e90x7801x6765x81eawww.xiaodao.la
Translation: 0x0804 0x04b0

Ransom.MBRLock.3 also known as:

K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.31327
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.MBRLock.3
CylanceUnsafe
SangforVirus_Suspicious.Win32.Sality.ae
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.3c7896
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MBRlock.BA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Zusy-6840460-0
KasperskyTrojan-Ransom.Win32.Foreign.naew
BitDefenderGen:Variant.Ransom.MBRLock.3
MicroWorld-eScanGen:Variant.Ransom.MBRLock.3
TencentWin32.Trojan.Foreign.Pdvl
Ad-AwareGen:Variant.Ransom.MBRLock.3
SophosGeneric ML PUA (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34608.fr0@aun9HIcb
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.MBRLOCKER.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.b1816673c78965a2
EmsisoftGen:Variant.Ransom.MBRLock.3 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Ransom.MBRlock.woltx
eGambitUnsafe.AI_Score_97%
MicrosoftTrojan:Win32/Emotet!ml
GDataGen:Variant.Ransom.MBRLock.3
AhnLab-V3Unwanted/Win32.HackTool.R187811
McAfeeArtemis!B1816673C789
MAXmalware (ai score=80)
MalwarebytesTrojan.FlyStudio
TrendMicro-HouseCallRansom.Win32.MBRLOCKER.SM
RisingRansom.Dexcrypt!1.B151 (RDMK:cmRtazr82HIjvMwxsrz3+68TLzb3)
IkarusTrojan.Win32.MBRlock
FortinetW32/MBRlock.BA!tr.ransom
AVGWin32:Trojan-gen
Qihoo-360Trojan.Win32.Made.I

How to remove Ransom.MBRLock.3?

Ransom.MBRLock.3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment