Ransom Trojan

What is “Trojan-Ransom.Win32.Locky.adyf”?

Malware Removal

The Trojan-Ransom.Win32.Locky.adyf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Locky.adyf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
apps.identrust.com
isrg.trustid.ocsp.identrust.com
crl.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine Trojan-Ransom.Win32.Locky.adyf?


File Info:

crc32: E194F270
md5: 9b04832d6515debb41513051a3e736df
name: 9B04832D6515DEBB41513051A3E736DF.mlw
sha1: 757471231dfd979dc27ff6a2d5cbf6a9d935a80f
sha256: b270188bf1b4eb46d344b5d019437139a2a3d8678660e9322a2990ee9e52080e
sha512: 55a382b817e0201dfc753d98d18e4ec5b4593b6263413f40d4bfe1de54972e473584acf2691813fe6815ad8dfbb5b13f19250d3d7a901298814d2bf60a2f2638
ssdeep: 12288:1nbSgr+MOb1q1XLxri2rD5psqW3721gunLHCM0qCnjrBDS:1nwMOb1qlxrTrD5Q3FuLiZDS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Locky.adyf also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0051918c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.13570
CynetMalicious (score: 100)
McAfeeGenericRXCG-LG!9B04832D6515
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1246482
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Locky.915594a0
K7GWTrojan ( 0051918c1 )
Cybereasonmalicious.d6515d
CyrenW32/Locky.BX.gen!Eldorado
SymantecRansom.Locky.B
ESET-NOD32a variant of Win32/Kryptik.FVTT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Locky-6335674-3
KasperskyTrojan-Ransom.Win32.Locky.adyf
BitDefenderGen:Heur.Ransom.Lukitos.1
NANO-AntivirusTrojan.Win32.Encoder.esccxj
ViRobotTrojan.Win32.Locky.673280.C
MicroWorld-eScanGen:Heur.Ransom.Lukitos.1
TencentMalware.Win32.Gencirc.1149783e
Ad-AwareGen:Heur.Ransom.Lukitos.1
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Ransom.Locky.FVTT@7br34s
BitDefenderThetaGen:NN.ZexaF.34770.PqX@aytLGmoi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.9b04832d6515debb
EmsisoftGen:Heur.Ransom.Lukitos.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Locky.djp
AviraHEUR/AGEN.1120889
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASMalwS.218FB72
MicrosoftRansom:Win32/Locky.A
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Trojan.Kryptik.IT
AhnLab-V3Win-Trojan/Lukitus3.Exp
Acronissuspicious
VBA32Trojan-Ransom.Cryptor
MAXmalware (ai score=85)
MalwarebytesMalware.AI.1687953590
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMALY0
RisingTrojan.Generic@ML.100 (RDML:hei2lZ0ctXnbLIPaA/psYA)
YandexTrojan.GenAsa!8azjoivMnBA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.APXF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Locky.HxQBEpsA

How to remove Trojan-Ransom.Win32.Locky.adyf?

Trojan-Ransom.Win32.Locky.adyf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment