Malware

CryptoLocker.29 removal guide

Malware Removal

The CryptoLocker.29 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What CryptoLocker.29 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Singapore)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

decorstal.pl
lovemydress.pl
iglesiaelrenacer.com
csopedro.org
fmc.org.in
ocsp.digicert.com
mhomeusa.com

How to determine CryptoLocker.29?


File Info:

crc32: F664C612
md5: 960bd8ec352202ac952c4dc0922c37e7
name: 960BD8EC352202AC952C4DC0922C37E7.mlw
sha1: c3c9c4ea7cec06094e0d2aff9b7ddb586452a3eb
sha256: bd707ef7caa79ad04f312d166b0cf8811b1829df0a34dccae181204b2f5ff56a
sha512: 77db3a9d773b9602c42053e9fe89e8c3dd9d7b888811df068ab1c6c3c577c6fa02e1119455386804a4c056ec7f74d9b45bcd2e24676fe70b4b9169353ccb82e9
ssdeep: 12288:WZNu2S6XH++7LEjKEykptuMT8z0fZjU3+7LEjKEykptuMT:WTvL++nEuXouMLfZjw+nEuXouM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014
InternalName: Premises
FileVersion: 0.164.2.178
CompanyName: Rockin' Software
PrivateBuild: 143, 159, 65, 133
LegalTrademarks: Small
Comments: Tankers
ProductName: Strict Refresher
SpecialBuild: 0.72.162.207
ProductVersion: 0.191.122.131
FileDescription: Tremor Rebuff Processors
OriginalFilename: Swappersl.EXE

CryptoLocker.29 also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Tpyn.x!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3967
ClamAVWin.Virus.TeslaCrypt3-2
CAT-QuickHealRansom.Teslacrypt.OL4
ALYacGen:Variant.CryptoLocker.29
CylanceUnsafe
ZillyaTrojan.Injector.Win32.362792
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Tescrypt.dea757e5
K7GWTrojan ( 0055e3991 )
K7AntiVirusTrojan ( 0055e3991 )
BaiduWin32.Trojan.Filecoder.k
CyrenW32/S-708004d4!Eldorado
SymantecRansom.TeslaCrypt
ESET-NOD32a variant of Win32/Injector.CSOF
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyPacked.Win32.Tpyn
BitDefenderGen:Variant.CryptoLocker.29
NANO-AntivirusTrojan.Win32.Encoder.eajhwd
ViRobotTrojan.Win32.TeslaCrypt.Gen.C
MicroWorld-eScanGen:Variant.CryptoLocker.29
TencentMalware.Win32.Gencirc.10c40068
Ad-AwareGen:Variant.CryptoLocker.29
SophosML/PE-A + Mal/Ransom-EC
ComodoMalware@#24zqoz58fkq3t
BitDefenderThetaGen:NN.ZexaF.34142.Nq1@aOxmZRkj
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.960bd8ec352202ac
EmsisoftGen:Variant.CryptoLocker.29 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.Shifu.em
AviraHEUR/AGEN.1111324
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1727913
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Tescrypt.H
ArcabitTrojan.CryptoLocker.29
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
GDataGen:Variant.CryptoLocker.29
AhnLab-V3Win-Trojan/Cryptolocker.Gen
Acronissuspicious
McAfeeRansomware-FEB!960BD8EC3522
MAXmalware (ai score=100)
VBA32TrojanBanker.Shifu
PandaTrj/TeslaCrypt.A
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
RisingTrojan.Agent!1.A322 (CLASSIC)
YandexTrojan.PWS.Shifu!FUjafEUsVJs
IkarusTrojan-Ransom.CryptoWall3
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EOVH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove CryptoLocker.29?

CryptoLocker.29 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment