Malware

About “CryptoLocker.28” infection

Malware Removal

The CryptoLocker.28 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What CryptoLocker.28 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine CryptoLocker.28?


File Info:

crc32: D4638BE3
md5: 39ac2b097d8131c4ffe18d89563035a0
name: 39AC2B097D8131C4FFE18D89563035A0.mlw
sha1: f8f612265ca8b58ed63828da711cde4cdae2bfcd
sha256: 329da1ff59501b4719b5ee7f5fcda9e9f60532f11f24c1078f83417a0d246b05
sha512: 80232ae2076bdb026627d6d5d32e54de20eee17f468c2b15693d4b10f144771813900be45292bc4c70e93e84c4ce494d4638fec1cca58fe0ca78d9e01e86fe59
ssdeep: 3072:2sSDMRmdna5RVPkkkK+rSjwH4gUghYq/WgNkt9cIx8:HSddaeTr+u44hYq/U78
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

CryptoLocker.28 also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.36603
CynetMalicious (score: 99)
ALYacGen:Variant.CryptoLocker.28
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.23785880
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.97d813
ESET-NOD32a variant of MSIL/Injector.BSK
APEXMalicious
AvastMSIL:Crypt-OG [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.blyr
BitDefenderGen:Variant.CryptoLocker.28
NANO-AntivirusTrojan.Win32.Blocker.bvkatl
MicroWorld-eScanGen:Variant.CryptoLocker.28
TencentWin32.Trojan.Blocker.Lmbk
Ad-AwareGen:Variant.CryptoLocker.28
SophosML/PE-A
ComodoMalware@#2hmi3q2bcg5ua
BitDefenderThetaGen:NN.ZemsilF.34126.jmW@aat4Lkp
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.39ac2b097d8131c4
EmsisoftGen:Variant.CryptoLocker.28 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.iub
WebrootW32.Trojan.GenKDV
AviraTR/Dropper.MSIL.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.9FEFEE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Rimod!gmb
ZoneAlarmTrojan-Ransom.Win32.Blocker.blyr
GDataGen:Variant.CryptoLocker.28
TACHYONTrojan/W32.DN-Blocker.160768.D
AhnLab-V3Trojan/Win32.Blocker.C1238258
McAfeeArtemis!39AC2B097D81
MAXmalware (ai score=100)
VBA32Hoax.Blocker
PandaGeneric Malware
YandexTrojan.Blocker!Bn82MSe+R0k
IkarusBackdoor.Win32.Fynloski
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.BLYR!tr
AVGMSIL:Crypt-OG [Trj]

How to remove CryptoLocker.28?

CryptoLocker.28 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment