Ransom

How to remove “Ransom.LockerGoga.16”?

Malware Removal

The Ransom.LockerGoga.16 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.LockerGoga.16 virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (14 unique times)
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

www.xhook.net
x1.i.lencr.org
www.bing.com
ocsp.digicert.com
assets.onestore.ms
statics-marketingsites-wcus-ms-com.akamaized.net
ajax.aspnetcdn.com
mem.gfx.ms
js.monitor.azure.com
cacerts.digicert.com
img-prod-cms-rt-microsoft-com.akamaized.net

How to determine Ransom.LockerGoga.16?


File Info:

crc32: 6B8D1270
md5: 2c54f82520b2b675abeebe1b39a6487c
name: 2C54F82520B2B675ABEEBE1B39A6487C.mlw
sha1: 6caa32c1933f6470180e37535b4e4d5b1833cf9a
sha256: af53eada5539eee1c8a190d82bc0fec18d03b415f360465335da6967605c4bdf
sha512: 054b994620d061348082a76ffae90230553fb17ce0626162206698b61dd8940ed67bb13dfdc997b6f3f5e4c2b10d8d0ed8e00d79d88b599a074691d851332754
ssdeep: 24576:GOddc13y6YVYRXVEGdyXnQdsAD5Qdr994aVjfEIVg18i/3iluZl5:zdWFgQuAD5Qdr9CIfEImL/3ilWl5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.LockerGoga.16 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusUnwanted-Program ( 00568e2f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.LockerGoga.16
CylanceUnsafe
AlibabaHackTool:Win32/LockerGoga.330557d6
K7GWUnwanted-Program ( 00568e2f1 )
Cybereasonmalicious.520b2b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.DJI potentially unsafe
APEXMalicious
AvastFileRepMalware
BitDefenderGen:Variant.Ransom.LockerGoga.16
MicroWorld-eScanGen:Variant.Ransom.LockerGoga.16
Ad-AwareGen:Variant.Ransom.LockerGoga.16
SophosGeneric PUA GM (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.jvW@airzl0ni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
FireEyeGeneric.mg.2c54f82520b2b675
EmsisoftGen:Variant.Ransom.LockerGoga.16 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.305C4EC
MicrosoftTrojan:Win32/Occamy.CAF
GDataGen:Variant.Ransom.LockerGoga.16
McAfeeArtemis!2C54F82520B2
MAXmalware (ai score=83)
VBA32BScope.Trojan.Swrort
YandexRiskware.Agent!dbjUYPVPLPg
FortinetRiskware/GameHack
AVGFileRepMalware

How to remove Ransom.LockerGoga.16?

Ransom.LockerGoga.16 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment