Ransom Trojan

How to remove “Trojan-Ransom.Win32.Locky.ackd”?

Malware Removal

The Trojan-Ransom.Win32.Locky.ackd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Locky.ackd virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of Locky ransomware
  • Mimics icon used for popular non-executable file format

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Locky.ackd?


File Info:

crc32: 1237AC4E
md5: a3df0221ee09082ac73d39fa8cf566cf
name: A3DF0221EE09082AC73D39FA8CF566CF.mlw
sha1: 037ba02f072b776bd0d4b1bf02af34c52a2c1ab8
sha256: ca0652a0e8e1a9cd6d5ad2e52921fd21ba35e064a8ab1b9cb50ad5bfc1758613
sha512: 3b5e828b8116afe9bb4eb1423aaa86a6fa71664b574d590a86d705f948c2a3681fef5ae2959a50bbad0532422ee0725f1fec66f4189566059166d43181da8e04
ssdeep: 6144:xC/fWGSEyyb6KduIzde8xeOQ+crO62cY8ppidZi:IWGvSKEIzdeseOhx67Y8psdZi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015 SUPERAntiSpyware
InternalName: Mission 1996
FileVersion: 4.8.62.5
CompanyName: SUPERAntiSpyware
LegalTrademarks: Copyright 2015 SUPERAntiSpyware
Comments: Soif Beams Nap Explains
ProductName: Mission 1996
Languages: English
ProductVersion: 4.8.62.5
FileDescription: Soif Beams Nap Explains
OriginalFilename: Mission 1996
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Locky.ackd also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056e8fe1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0056e8fe1 )
Cybereasonmalicious.f072b7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FNKJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Locky.ackd
NANO-AntivirusTrojan.Win32.Locky.fhkhue
TencentWin32.Trojan.Locky.Lnoh
SophosMal/Generic-S + Mal/Kryptik-DC
ComodoMalware@#10sfrqqvgno5e
BitDefenderThetaGen:NN.ZexaF.34088.uu0@a02CRghi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SME1
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.a3df0221ee09082a
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1102805
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASMalwS.22B7880
MicrosoftRansom:Win32/Locky
Acronissuspicious
McAfeeArtemis!A3DF0221EE09
MAXmalware (ai score=99)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesRansom.Cerber
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPLOCKY.SME1
RisingTrojan.Generic@ML.85 (RDML:LQibjyuQJiRA4uG+1OHrwA)
YandexTrojan.Locky!dLrUqTdhO9Y
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.EJXP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Locky.ackd?

Trojan-Ransom.Win32.Locky.ackd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment