Trojan

Trojan.CryptoLocker.AR (file analysis)

Malware Removal

The Trojan.CryptoLocker.AR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.CryptoLocker.AR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Hongkong)
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Trojan.CryptoLocker.AR?


File Info:

crc32: D6E4F24B
md5: 2a3ac47662b55f85bd1bd2beb9826685
name: 2A3AC47662B55F85BD1BD2BEB9826685.mlw
sha1: 353a9cd72b26cb7dc0bdb47324b5d41ef01f6413
sha256: 455266375ce35157cb22c5baef1c2bbac42cefcbbe88eff04bb527acde604eb2
sha512: 8dab0026e36d2c08abdcfe641036cb5abfa25133b16b6c6982f7bea94b3fdff9e46f6729780e25b27a6b8015ec00e59ab11ce8cd0480c99671c356acb0999cd0
ssdeep: 6144:NRH/9e6kTFrTEUG/haRu+7ADVmQGt5/ur0gsAqVGCxapft6J:NN9e6aTPG/haRu6AslPGrvswC8pf6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Manufacturing xa9 2059
InternalName: Ids
FileVersion: 205, 145, 8, 96
CompanyName: scar5 Software
ProductName: Ocelots Minor
FileDescription: Globetrotting
OriginalFilename: Highlighter.exe

Trojan.CryptoLocker.AR also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader16.3408
CynetMalicious (score: 100)
CAT-QuickHealRansom.TeslaCrypt.WR4
ALYacTrojan.CryptoLocker.AR
CylanceUnsafe
ZillyaTrojan.Bitman.Win32.468
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Bitman.0ad67e45
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.662b55
SymantecPacked.Generic.490
ESET-NOD32Win32/Filecoder.TeslaCrypt.E
APEXMalicious
AvastWin32:TeslaCrypt-EE [Trj]
KasperskyTrojan-Ransom.Win32.Bitman.yq
BitDefenderTrojan.CryptoLocker.AR
NANO-AntivirusTrojan.Win32.Bitman.dvwauz
MicroWorld-eScanTrojan.CryptoLocker.AR
TencentMalware.Win32.Gencirc.114c7ad1
Ad-AwareTrojan.CryptoLocker.AR
SophosMal/Generic-R + Mal/Tinba-L
ComodoMalware@#2wda6yxqegfyj
BitDefenderThetaGen:NN.ZexaF.34628.vu3@aqnz5iiH
VIPRETrojan.Win32.Generic!BT
TrendMicroCryp_HpMyApp
McAfee-GW-EditionBehavesLike.Win32.Trojan.fc
FireEyeGeneric.mg.2a3ac47662b55f85
EmsisoftTrojan.CryptoLocker.AR (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Bitman.go
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1125260
eGambitGeneric.Malware
MicrosoftRansom:Win32/Tescrypt.A
ArcabitTrojan.CryptoLocker.AR
GDataTrojan.CryptoLocker.AR
AhnLab-V3Trojan/Win32.Tescrypt.C957661
McAfeeTeslaCrypt!2A3AC47662B5
MAXmalware (ai score=100)
VBA32Hoax.Bitman
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_HpMyApp
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.GenAsa!PGqz4iMeECw
IkarusTrojan.Win32.Filecoder
FortinetW32/Papras.EH!tr
AVGWin32:TeslaCrypt-EE [Trj]
Qihoo-360Win32/Ransom.Bitman.HwcBEpsA

How to remove Trojan.CryptoLocker.AR?

Trojan.CryptoLocker.AR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment