Trojan

MemScan:Trojan.CryptoLocker.DI removal

Malware Removal

The MemScan:Trojan.CryptoLocker.DI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.CryptoLocker.DI virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Japanese
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware

Related domains:

z.whorecord.xyz
a.tomx.xyz
afdvokebqepmj.fr
cglxsdshiux.nl
leyoticst.tf

How to determine MemScan:Trojan.CryptoLocker.DI?


File Info:

crc32: 98829343
md5: d402ee194553b94ab640f4b77c4d269c
name: D402EE194553B94AB640F4B77C4D269C.mlw
sha1: b6c5a3cbb696223aa9fc7122fdcbb65bd24a33b8
sha256: 3ea2ae8f56d853bc221239ea0c0ce19046b351548f7a87110daacee41edec165
sha512: b08c524c3fe5c36dc385c3de0ad47a4155b4d0c4a84bca2dbb8cba67d8ac8ba96659670b45fa4ad5c22175d9e5cd07b1115d7ae0991517ffe9003395a41ec158
ssdeep: 3072:i1yoPtIxyQuerZULnEgfYs/m2S7pFYq31ANEqf2lH4opo2EtifRCAr2ZBCRmWMH:8VtSdUogwsnSBlAaB4ojPR46
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2013
InternalName: Amass
FileVersion: 155, 53, 147, 79
CompanyName: RadarSync LTD
ProductName: Utterance Candidatures
ProductVersion: 242, 11, 256, 113
FileDescription: Unreceptive

MemScan:Trojan.CryptoLocker.DI also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Locky.j!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader19.38965
CynetMalicious (score: 100)
CAT-QuickHealRansom.TesCrypt.V4
ALYacMemScan:Trojan.CryptoLocker.DI
CylanceUnsafe
ZillyaTrojan.CryptGen.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.94553b
CyrenW32/Locky.N.gen!Eldorado
SymantecRansom.TeslaCrypt
ESET-NOD32Win32/Filecoder.Locky.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderMemScan:Trojan.CryptoLocker.DI
NANO-AntivirusTrojan.Win32.Dwn.ebditx
ViRobotTrojan.Win32.Locky.Gen.C
MicroWorld-eScanMemScan:Trojan.CryptoLocker.DI
TencentWin32.Trojan.Filecoder.Wnvm
Ad-AwareMemScan:Trojan.CryptoLocker.DI
SophosML/PE-A + Troj/Ransom-CYD
BitDefenderThetaGen:NN.ZexaF.34110.mq0@ai1F8@jO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SM1
McAfee-GW-EditionGamarue-FDR!D402EE194553
FireEyeGeneric.mg.d402ee194553b94a
EmsisoftMemScan:Trojan.CryptoLocker.DI (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Locky.hb
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1108100
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.382E
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Locky.A
ArcabitTrojan.CryptoLocker.DI
GDataMemScan:Trojan.CryptoLocker.DI
AhnLab-V3Win-Trojan/Lockycrypt.Gen
McAfeeGamarue-FDR!D402EE194553
MAXmalware (ai score=80)
VBA32BScope.TrojanDownloader.Talalpek
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPLOCKY.SM1
IkarusTrojan-Ransom.TeslaCrypt4
FortinetW32/Kryptik.ESPA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MemScan:Trojan.CryptoLocker.DI?

MemScan:Trojan.CryptoLocker.DI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment