Ransom Trojan

About “Trojan-Ransom.Cryptolocker (A)” infection

Malware Removal

The Trojan-Ransom.Cryptolocker (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Cryptolocker (A) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Cryptolocker (A)?


File Info:

crc32: CE929CFA
md5: 169db124e32bd3918560986f6f9870d8
name: 169DB124E32BD3918560986F6F9870D8.mlw
sha1: 17ef9d6344b345556addb401e05e0f0e6650e3f0
sha256: 236fbe3180909d5a3e93d4fac0418cdc1f5c1d70d343103061f550c1d8372ae5
sha512: c52e9d2b259ab9926a2c0623e7406e8f97304bdd105d7ba75eff9a566a62f8c76cbdcdc1a879310bc7b860c5bdb6bfce69a96030fb08f07aaaeea8f19b8d0c44
ssdeep: 6144:+wHysEXGlYYlJ8cUbp4ZjAm+d1nFlQKJw6wXMjVrYWNejFJ9zeF2eFL:1EX8Y+8jp4Zkm+XxK1MjVVoJOFl1
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Cryptolocker (A) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005097001 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
CynetMalicious (score: 99)
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.5995
SangforTrojan.Win32.Heuristic.rg
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005097001 )
Cybereasonmalicious.4e32bd
SymantecRansom.CryptXXX
ESET-NOD32Win32/Filecoder.TorrentLocker.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Nisloder.dhw
BitDefenderGen:Heur.Mint.Titirez.wuZ@Vi80yHei
NANO-AntivirusTrojan.Win32.Enestedel.emvwnn
MicroWorld-eScanGen:Heur.Mint.Titirez.wuZ@Vi80yHei
TencentNsis.Trojan.Sod.Dyqv
Ad-AwareGen:Heur.Mint.Titirez.wuZ@Vi80yHei
SophosMal/Generic-R + Troj/Zbot-LRY
ComodoMalware@#3nxucnm9bq6rr
BitDefenderThetaGen:NN.ZedlaF.34294.bu4@a8XpAvoi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTLOCK.F117CM
McAfee-GW-EditionW32/Teerac.b
FireEyeGeneric.mg.169db124e32bd391
EmsisoftTrojan-Ransom.Cryptolocker (A)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1124320
KingsoftWin32.Troj.Generic.v.(kcloud)
MicrosoftRansom:Win32/Enestaller.V!rsm
ArcabitTrojan.Mint.Titirez.ED58B8
SUPERAntiSpywareRansom.CryptoLocker/Variant
GDataGen:Heur.Mint.Titirez.wuZ@Vi80yHei
McAfeeW32/Teerac.b
MAXmalware (ai score=100)
VBA32Trojan.Nisloder
PandaTrj/RansomCrypt.E
TrendMicro-HouseCallRansom_CRYPTLOCK.F117CM
RisingTrojan.Generic@ML.87 (RDML:NyCTE/dv6kS17hPvoLw+ew)
YandexTrojan.Injector!XfSdbMKvzwc
FortinetW32/Injector.DMWR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Cryptolocker (A)?

Trojan-Ransom.Cryptolocker (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment