Ransom

How to remove “Ransom:Win32/Locky.SA!MTB”?

Malware Removal

The Ransom:Win32/Locky.SA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Locky.SA!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (8 unique times)
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
bit.do
rebrand.ly
jamshed.pk
backgrounds.pk
karimgousa.ug
telete.in
karimgouss.ug
apps.identrust.com
morasergiov.ac.ug
jamesrlongacre.ug
ourmainpriority.com

How to determine Ransom:Win32/Locky.SA!MTB?


File Info:

crc32: CDB5DA3A
md5: 70fb5e54ff3ba4682fd382c10493ef0e
name: upload_file
sha1: 8273c8f09b281f78bfc3055603aa1f8954a39ce3
sha256: bb88b0e196c6418b7b3e20f9703cfc4bc4b7fcbe2afbb0c320abe063e1b7fc8f
sha512: 0aac50c66bdf3c30fc283865a8d4537fe4180580191f989a9e48d666ccd5e42e22ed6aeffb6a3e8f676defec7e65b9c8f9d8657b004328e27650285fa66ef07a
ssdeep: 3072:l3C/C1Csg3kxSAtb35ijMjlXOUCJWjhh29oimz4uyvNLo:l9SAtVijMRXOtJWth29ozzUFLo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Locky.SA!MTB also known as:

Elasticmalicious (high confidence)
ClamAVWin.Trojan.VBGeneric-8264807-0
FireEyeGeneric.mg.70fb5e54ff3ba468
McAfeeFareit-FST!70FB5E54FF3B
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056934d1 )
BitDefenderGen:Variant.Graftor.783682
K7GWTrojan ( 0056934d1 )
Cybereasonmalicious.4ff3ba
InvinceaMal/Generic-S
CyrenW32/Kryptik.BPB.gen!Eldorado
SymantecInfostealer
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Razy.hlkpnp
MicroWorld-eScanGen:Variant.Graftor.783682
RisingTrojan.Injector!1.C6AF (CLASSIC)
Ad-AwareGen:Variant.Graftor.783682
EmsisoftGen:Variant.Graftor.783682 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen9.55566
ZillyaTrojan.Chapak.Win32.86089
McAfee-GW-EditionFareit-FST!70FB5E54FF3B
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
JiangminTrojan.PSW.Racealer.axd
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Chapak
MicrosoftRansom:Win32/Locky.SA!MTB
ArcabitTrojan.Graftor.DBF542
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Graftor.783682
BitDefenderThetaGen:NN.ZevbaF.34570.tnZ@aydw5WBi
ALYacGen:Variant.Graftor.783682
VBA32TScope.Trojan.VB
MalwarebytesBackdoor.NanoCore
ESET-NOD32a variant of Win32/Injector.EMLN
TencentMalware.Win32.Gencirc.10cdd799
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_95%
FortinetW32/Injector.EMPE!tr
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.A3A3.Malware.Gen

How to remove Ransom:Win32/Locky.SA!MTB?

Ransom:Win32/Locky.SA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment