Malware

Locky.8 (file analysis)

Malware Removal

The Locky.8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Locky.8 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Locky.8?


File Info:

crc32: 47B72AE1
md5: 7e842e86a97c7f9d199dd9882100bd5a
name: KOSTENNOTE-299304826345.PDF.exe
sha1: 3713b11da8d03b7a622ec313e3cc993477abbda0
sha256: 8ec6938c9c006113f9622c71f881ac46e6dcf14a1ad4ac755256afbbbb2decc7
sha512: a7dabfd265e7115ae8e00e5ed6bea31b413ad89373982379c6af856a682108551f5ed7e5eb2eeaee405675a10b58fbdc03ad16a3e33f0debe4bb1e310bccc360
ssdeep: 6144:HpkXGh6uU+UCXkrPJXJrYAHprr2UwVm5Vi9UQdAEykYf0PhBsBrhjG2z:afuUKULJXRH4Nm5fzESSsBxj
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Locky.8 also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Locky.8
FireEyeGeneric.mg.7e842e86a97c7f9d
CAT-QuickHealTrojan.Crypt
McAfeeRDN/Generic.dx
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00560a5a1 )
AlibabaTrojan:Win32/Injector.65b17908
K7GWTrojan ( 00560a5a1 )
Cybereasonmalicious.6a97c7
ESET-NOD32a variant of Win32/Injector.EKOI
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Noon-7609639-0
GDataTrojan.GenericKD.33337687
KasperskyHEUR:Trojan.NSIS.Agent.gen
BitDefenderGen:Variant.Locky.8
AegisLabTrojan.Win32.Crypt.4!c
AvastWin32:Trojan-gen
TencentNsis.Trojan.Agent.Akzc
EmsisoftGen:Variant.Locky.8 (B)
F-SecureHeuristic.HEUR/AGEN.1047029
DrWebTrojan.Siggen9.13555
ZillyaTrojan.Crypt.Win32.61150
TrendMicroRansom.Win32.NEMTY.Q
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.fc
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.YPQI-5957
AviraHEUR/AGEN.1047029
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FCB157
ViRobotTrojan.Win32.Z.Locky.375142
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C4008951
BitDefenderThetaGen:NN.ZexaF.34104.cu0@ay7Jick
MAXmalware (ai score=81)
VBA32BScope.Backdoor.NetWiredRC
TrendMicro-HouseCallRansom.Win32.NEMTY.Q
RisingTrojan.Generic@ML.85 (RDML:sUmZ4UbXJPn4RATsIpKZkw)
YandexTrojan.Injector!FQ2ZYyyQmP8
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_79%
FortinetW32/EKOI!tr
MaxSecureTrojan.Malware.11604479.susgen
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.ed1

How to remove Locky.8?

Locky.8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment