Malware

Application.Locky.6 information

Malware Removal

The Application.Locky.6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Locky.6 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Application.Locky.6?


File Info:

name: CD86D7016FCAAB02866B.mlw
path: /opt/CAPEv2/storage/binaries/b868c0ff853be61069c10b9ea89ad9313dd3e2b311aa958d095d12025b0789fd
crc32: AE68D0AC
md5: cd86d7016fcaab02866b313cac63b441
sha1: 2fc154d402e3d1be721bbf11890735a4c96ef5ac
sha256: b868c0ff853be61069c10b9ea89ad9313dd3e2b311aa958d095d12025b0789fd
sha512: e64a1fa74d2bd81f75044e8fced87d14a5642c6c8e8f7fc6875d78ee2e0f03e55b4f9814ca7ac57e7675a1c84b4fe5e3759f96c7fe2a431bf7d615e85f7cb8c2
ssdeep: 6144:FMMMxihEoUc/npYUPLFI4CQotBevpQUikT79f1GB35L/WGl7g+Lu:FMMMQhEoUKnKUjqDXBevpQxQJtGBpLOB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15074F242F4F46C6FFC613736A78A21305E99AC5E3B018B9760C16D1EFF63093991A19B
sha3_384: c610374afac9974745a6cc03524f3397285a50125814c2537d2bc41cc4fe8c0e33a500b742c5d827360edb0cddc21634
ep_bytes: 558bec51568bf58975fc8b45fc50e8ed
timestamp: 2013-01-24 18:12:50

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Windows Setup Utility
FileVersion: 9.00.00.4503
InternalName: a6ize
LegalCopyright: (C) Microsoft Corporation. All rights reserved.
OriginalFilename: a6ize
ProductName: Microsoft(R) Windows Media Player
ProductVersion: 9.00.00.4503
Translation: 0x0409 0x04b0

Application.Locky.6 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lIty
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.cd86d7016fcaab02
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeePWS-Zbot.gen.xd
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.97973
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0040f0ce1 )
AlibabaTrojanPSW:Win32/Reveton.a6a57e45
K7GWTrojan-Downloader ( 0040f0ce1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.BLCJ
CyrenW32/Zbot.KG.gen!Eldorado
SymantecTrojan.Zbot!g38
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
ClamAVWin.Trojan.Zbot-30438
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Application.Locky.6
NANO-AntivirusTrojan.Win32.Panda.bfohne
SUPERAntiSpywareTrojan.Agent/Gen-FakeMS
MicroWorld-eScanGen:Variant.Application.Locky.6
AvastWin32:Karagany
TencentMalware.Win32.Gencirc.116b0bdb
Ad-AwareGen:Variant.Application.Locky.6
SophosMal/Generic-R + Troj/Zbot-DPK
ComodoTrojWare.Win32.Spy.ZBot.EB@4uei1b
DrWebTrojan.PWS.Panda.3528
VIPRETrojan.Win32.Agent.akm (v)
TrendMicroTSPY_ZBOT.SM20
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftGen:Variant.Application.Locky.6 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Application.Locky.6
JiangminTrojan/Generic.audxu
WebrootW32.Trojan.Gen
AviraTR/Kryptik.445879
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.1391A0
KingsoftWin32.Troj.Zbot.a.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!GO
AhnLab-V3Spyware/Win32.Zbot.R49955
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.vq0@aqVJx6Ci
ALYacGen:Variant.Application.Locky.6
TACHYONTrojan-Spy/W32.ZBot.349696.AB
VBA32BScope.Malware-Cryptor.SB.01798
MalwarebytesMalware.AI.2536813561
TrendMicro-HouseCallTSPY_ZBOT.SM20
RisingTrojan.Crypto!8.364 (CLOUD)
YandexTrojan.GenAsa!i4IWC/QY2tM
IkarusTrojan.Win32.Pakes
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AAU!tr
AVGWin32:Karagany
Cybereasonmalicious.16fcaa
PandaTrj/Hexas.HEU

How to remove Application.Locky.6?

Application.Locky.6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment