Ransom

Should I remove “Generic.Ransom.Locky.676F3537”?

Malware Removal

The Generic.Ransom.Locky.676F3537 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Locky.676F3537 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Locky malware family
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Appends a known Locky ransomware file extension to files that have been encrypted
  • Creates a known Locky ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Locky.676F3537?


File Info:

name: D4815518BE95074411B3.mlw
path: /opt/CAPEv2/storage/binaries/a96f0009ea638aeb41caa1af6476fa78f15737b4acb722d380c5911b1ee2ea3c
crc32: 4185C498
md5: d4815518be95074411b318b3c49b6e4b
sha1: de22aa333db97f188042cd251cfee6301dc11294
sha256: a96f0009ea638aeb41caa1af6476fa78f15737b4acb722d380c5911b1ee2ea3c
sha512: eeab6cdd6e67aa76e376447a948a62407f7561cd12e2bb4e0f29f0833a74f2efbf0c0a0ec14e8749da5aad20e7b0d26b80ba96df5b91c8ae88f7254dfc7fc97a
ssdeep: 3072:Haok+l9BrtPYPsZjRGRgVmJdfxT2pkJAKnecZGuv0vh:Haok+l5BZRGRBJ1xTekJ7ecU1v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104E37D3231D0C271C4731535E9A9B6A17DBDF8F09DA14787A39806BE7E916C08AB4F87
sha3_384: 6416f06b59949a6221758ad92dcabf229c1dc7ea6d8c6778260167ef46d1852dd93864a530eaf02af6ad15c9b6409668
ep_bytes: 558bec83ec185356576a00ff15ac7141
timestamp: 2007-03-11 10:28:32

Version Info:

0: [No Data]

Generic.Ransom.Locky.676F3537 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Ransom.Locky.676F3537
ClamAVWin.Ransomware.Locky-30744
FireEyeGeneric.mg.d4815518be950744
CAT-QuickHealRansomware.Locky.MUE.G5
McAfeeTrojan-FLFH!D4815518BE95
VIPREGeneric.Ransom.Locky.676F3537
SangforRansom.Win32.Locky_7.se
K7AntiVirusTrojan ( 004eff041 )
BitDefenderGeneric.Ransom.Locky.676F3537
K7GWTrojan ( 004eff041 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.CryptLocky.DY
CyrenW32/Locky.HM.gen!Eldorado
SymantecRansom.TeslaCrypt
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Locky.C
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Locky.wqv
NANO-AntivirusTrojan.Win32.Locky.emuvzb
RisingRansom.Locky!8.1CD4 (TFE:1:fhNw43oaz5J)
Ad-AwareGeneric.Ransom.Locky.676F3537
SophosML/PE-A
ComodoTrojWare.Win32.Ransom.Locky.N@6q353j
DrWebTrojan.Encoder.3976
ZillyaTrojan.Locky.Win32.2361
TrendMicroRansom_LOCKY.SM3
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
EmsisoftGeneric.Ransom.Locky.676F3537 (B)
IkarusTrojan-Ransom.Locky
JiangminTrojan.Locky.cvs
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1229022
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.4855
MicrosoftRansom:Win32/Locky.A
GDataWin32.Trojan-Ransom.Locky.CT
GoogleDetected
AhnLab-V3Trojan/Win32.Locky.R184190
BitDefenderThetaAI:Packer.3B5A75331E
ALYacGeneric.Ransom.Locky.676F3537
TACHYONRansom/W32.Locky.145408
VBA32TScope.Malware-Cryptor.SB
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_LOCKY.SM3
TencentMalware.Win32.Gencirc.10b9f968
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.3BA8CE!tr
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.8be950
AvastWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.Locky.676F3537?

Generic.Ransom.Locky.676F3537 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment