Ransom Trojan

What is “Trojan-Ransom.Win32.Locky.cnu”?

Malware Removal

The Trojan-Ransom.Win32.Locky.cnu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Locky.cnu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Reads data out of its own binary image
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Locky.cnu?


File Info:

crc32: 6741F5CA
md5: 26ef1e269a5b87f01520e39bd97f4e98
name: 26EF1E269A5B87F01520E39BD97F4E98.mlw
sha1: fe907cd3a6f7e7c73a530cd791752a444c11c693
sha256: 7c9aa63bd228203d87caccb7b1e75b56d3eb90d43d7ccc4290c1a4fedc4e74da
sha512: 4dfa6a2b89beb53ff9fcc4c4607b4f0306a2c4c46bccf2c49bc0f734a0485bbd9a8b3c474e08ebbbd23ef0edd951e70dbf3d977059cffce96f409edc3e7e8ed2
ssdeep: 6144:zW+7+eMtWcGurBhqU0Fzm0Q273rLPMM0aWRrGH:zRYxGuFhpmQ273rL0M0KH
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Locky.cnu also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004fabcd1 )
DrWebTrojan.Encoder.3976
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.3603570
CylanceUnsafe
ZillyaDropper.Generic.Win32.2641
SangforRansom.Win32.Locky.cnu
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Locky.e0e103c8
K7GWTrojan ( 004fabcd1 )
Cybereasonmalicious.69a5b8
SymantecRansom.TeslaCrypt
ESET-NOD32Win32/Filecoder.Locky.C
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Locky-31487
KasperskyTrojan-Ransom.Win32.Locky.cnu
BitDefenderTrojan.GenericKD.3603570
NANO-AntivirusTrojan.Win32.Encoder.eikefz
MicroWorld-eScanTrojan.GenericKD.3603570
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.3603570
SophosMal/Generic-R + Mal/Miuref-L
ComodoMalware@#2hgrls4yv576g
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_LOCKY.JE
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.dc
FireEyeGeneric.mg.26ef1e269a5b87f0
EmsisoftTrojan.GenericKD.3603570 (B)
WebrootW32.Ransom.Gen
AviraTR/Dropper.Gen
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Locky.A
ArcabitTrojan.Generic.D36FC72
AegisLabTrojan.Win32.Locky.4!c
GDataTrojan.GenericKD.3603570
TACHYONRansom/W32.Locky.212597
AhnLab-V3Trojan/Win32.Locky.R189026
McAfeeArtemis!26EF1E269A5B
MAXmalware (ai score=100)
VBA32TrojanRansom.Locky
PandaTrj/CI.A
TrendMicro-HouseCallRansom_LOCKY.JE
FortinetW32/Injector.GP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Locky.HyoDVxcA

How to remove Trojan-Ransom.Win32.Locky.cnu?

Trojan-Ransom.Win32.Locky.cnu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment