Ransom

Ransom:Win32/Molock!rfn removal tips

Malware Removal

The Ransom:Win32/Molock!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Molock!rfn virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM

How to determine Ransom:Win32/Molock!rfn?


File Info:

crc32: 2327B319
md5: bd7de3321fb7dc9ab97234363576e578
name: BD7DE3321FB7DC9AB97234363576E578.mlw
sha1: b6f76b54772b1770083664cb96a436a54ce2c4fb
sha256: 0e3d03d6923f8b185dffec7f7c0a99224c00f4c858f13ba64b6a06059a7f416c
sha512: e8340a82f9c9ddefa410927a4c181b10e98e1ecac72426e8710b680df71b5db19ecde54c1b77a1d6de0395c2229655e38c8406182f01ee33e6ca8171e2d618f0
ssdeep: 12288:kALuA5NQAV+vku7IvLBs7y/jMwVK4BvPF8PtOQbLsCk:kAoAVskOIvtr/owVK4JPmVOQbLtk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7121x540d x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: x7121x540d
Comments: x7121x540d
ProductName: x7121x540dQQ2607682961
ProductVersion: 1.0.0.0
FileDescription: x8fd9x662fx4e00x6b3ex7528x7121x540dx751fx6210x5668x751fx6210x7684x8f6fx4ef6x54e6xff01
Translation: 0x0804 0x04b0

Ransom:Win32/Molock!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.29426
CynetMalicious (score: 100)
ALYacGeneric.Ransom.MBRLock.F180AE26
CylanceUnsafe
SangforRansom.Win32.Foreign.naew
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Foreign.59895f75
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.21fb7d
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MBRlock.AQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.naew
BitDefenderGeneric.Ransom.MBRLock.F180AE26
NANO-AntivirusTrojan.Win32.MBRLock.esqbvw
MicroWorld-eScanGeneric.Ransom.MBRLock.F180AE26
TencentWin32.Trojan.Foreign.Piaf
Ad-AwareGeneric.Ransom.MBRLock.F180AE26
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34608.az0@aq0Iu5mb
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.MBRLOCKER.SM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tm
FireEyeGeneric.mg.bd7de3321fb7dc9a
EmsisoftGeneric.Ransom.MBRLock.F180AE26 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.daf
AviraTR/MBRlock.zzkxf
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Molock!rfn
ArcabitGeneric.Ransom.MBRLock.F180AE26
AegisLabTrojan.Win32.Generic.lQvU
GDataWin32.Trojan.PSE.1U8NZ9I
Acronissuspicious
McAfeeArtemis!BD7DE3321FB7
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Foreign
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.MBRLOCKER.SM
RisingRansom.MBRlock!1.B6DC (CLOUD)
YandexTrojan.Foreign!ufjiA9C9JVk
IkarusTrojan.Win32.MBRlock
FortinetW32/MBRlock.AQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Foreign.HgIASOkA

How to remove Ransom:Win32/Molock!rfn?

Ransom:Win32/Molock!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment