Ransom Trojan

Trojan.Ransom.JohnsLocker removal tips

Malware Removal

The Trojan.Ransom.JohnsLocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.JohnsLocker virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Trojan.Ransom.JohnsLocker?


File Info:

crc32: ECB0BFEF
md5: 0ea7a32007ed03fc767e4d01a521d919
name: 0EA7A32007ED03FC767E4D01A521D919.mlw
sha1: 0fa89a1309e533cc24f1a9903d372ecebd01b319
sha256: 6171323b3420d533b5855f71dda960f47c32c7bf5f0bbb5f6912f35253715fcc
sha512: 5074a1f132015eb412b073837def2175941c995a38ad4b2c2db61c36944f61eeeb86c564d88f0137ffa46ee70e43a7e61bc1326c4adb8018020ddd4f5e1eb57b
ssdeep: 1536:VLHXkF7kbtXwxc+ILHXkFwystUlmFrsNGq/afp3oGLHXkF:pH0F78N2DgH0FwZgraCOH0F
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: WindowsApplication1.exe
FileVersion: 1.0.0.0
Comments: File Encryption
ProductName: John's Ransomware
ProductVersion: 1.0.0.0
FileDescription: John's Ransomware
OriginalFilename: WindowsApplication1.exe

Trojan.Ransom.JohnsLocker also known as:

K7AntiVirusTrojan ( 005440141 )
LionicHacktool.Win32.Generic.3!c
DrWebTrojan.FakeEncoder.2
CynetMalicious (score: 99)
ALYacTrojan.Ransom.JohnsLocker
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.86622
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRiskWare:Win32/FakeFilecoder.dca81662
K7GWTrojan ( 005440141 )
Cybereasonmalicious.007ed0
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Hoax.FakeFilecoder.DU
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Hoax.Win32.Generic
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusRiskware.Win32.FakeRansom.etcqwh
ViRobotTrojan.Win32.S.Ransom.1164288
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
TencentMalware.Win32.Gencirc.114d8314
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
ComodoMalware@#3zwe96ob076j
BitDefenderThetaGen:NN.ZemsilF.34170.hr0@aWNAi3o
VIPREHoax.Win32.FakeRansom (not malicious)
FireEyeGen:Heur.Ransom.REntS.Gen.1
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
JiangminHoax.FakeRansom.c
AviraTR/Redcap.iirhk
Antiy-AVLTrojan/Generic.ASMalwS.21E62D4
KingsoftWin32.Torj.Hoax.(kcloud)
MicrosoftTrojan:Win32/Occamy.C61
GDataGen:Heur.Ransom.REntS.Gen.1
TACHYONJoke/W32.DN-FakeRansom.1164288
AhnLab-V3Trojan/Win32.FakeRansom.C2185538
McAfeeRansom-JLocker!0EA7A32007ED
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
YandexHoax.FakeFilecoder!49e2PXaNpI0
IkarusTrojan-Ransom.Hoax.John
MaxSecureTrojan.Malware.10685503.susgen
FortinetRiskware/FakeRansom
AVGWin32:Malware-gen

How to remove Trojan.Ransom.JohnsLocker?

Trojan.Ransom.JohnsLocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment