Ransom Trojan

Trojan.Ransom.LockyCrypt information

Malware Removal

The Trojan.Ransom.LockyCrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.LockyCrypt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings

How to determine Trojan.Ransom.LockyCrypt?


File Info:

crc32: 9C73AF04
md5: 2745d0b52d42b8e17f5e048c08329d8b
name: 2745D0B52D42B8E17F5E048C08329D8B.mlw
sha1: 984cd7534e3c7ffe527577fd6b57856aac27d1ed
sha256: fe418c4ff08ed669423d50efc41ebf026e72fae97ceabe04e9539ababfab1631
sha512: 39c6547dea48390d812743a1763fc32a606e5e81479aa1ceef694d9703c0eeb9700b1244dba43d28a9616048632a57073b7a072359f43fd4791cc89100aa8035
ssdeep: 12288:Rftq8213MaAOYetrMrM0uPDzcjmA13QwncT0GT7t5uHc:RfE8MMatYerMNu78h13QIcTJvt2
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.LockyCrypt also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051918c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.13570
CynetMalicious (score: 100)
ALYacTrojan.Ransom.LockyCrypt
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7971
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000027
K7GWTrojan ( 0051918c1 )
Cybereasonmalicious.52d42b
CyrenW32/Locky.CP.gen!Eldorado
SymantecRansom.Locky.B
ESET-NOD32Win32/Filecoder.Locky.M
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Tofsee-6345150-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Locky.DT
NANO-AntivirusTrojan.Win32.Encoder.ethher
ViRobotTrojan.Win32.U.Locky.593920
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanTrojan.Ransom.Locky.DT
TencentMalware.Win32.Gencirc.10bac53c
Ad-AwareTrojan.Ransom.Locky.DT
SophosML/PE-A + Mal/Elenoocka-E
ComodoBackdoor.Win32.Poison.FXLW@7ayjdi
BitDefenderThetaGen:NN.ZexaF.34678.KqW@aymqqJe
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionBehavesLike.Win32.VirRansom.hc
FireEyeGeneric.mg.2745d0b52d42b8e1
EmsisoftTrojan.Ransom.Locky.DT (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Locky.dna
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1120889
eGambitUnsafe.AI_Score_96%
MicrosoftRansom:Win32/Locky.A
ArcabitTrojan.Ransom.Locky.DT
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Trojan.Kryptik.IY
AhnLab-V3Win-Trojan/RansomCrypt.Exp
Acronissuspicious
McAfeeRansomware-GHE!2745D0B52D42
VBA32BScope.Trojan.Zbot.2312
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMALY0
RisingTrojan.Kryptik!1.AE11 (CLOUD)
YandexTrojan.GenAsa!K4CDtcabcwE
IkarusTrojan-Ransom.Locky
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BHMX!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Locky.HxQBEpsA

How to remove Trojan.Ransom.LockyCrypt?

Trojan.Ransom.LockyCrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment