Ransom Trojan

Trojan-Ransom.Winlock removal

Malware Removal

The Trojan-Ransom.Winlock is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Winlock virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Trojan-Ransom.Winlock?


File Info:

crc32: B655E592
md5: 774db116668b0df99c260b519710cead
name: 743cf459d142f656.exe
sha1: 5b9d080b851d1e3b489e04c61a6d91a5a7db77c7
sha256: ebbd1c49105282e3a4aedcdfa8310fa3d904e0dd6cc1408ca9e17eccff5ddd20
sha512: 3aaa47e49de2f8bb72cbcf760d89c38fd24ab545692e05721ba082dbbd62824dd08c58e51d7e7bc13c647709b3f72cc56fbb68d883a87318d0d48b8e09fa69d7
ssdeep: 12288:/2ghLvPhXpe3PlLF+OnGbuxn4rLN/uQC6vsd9zHvTqE2X9h2wHPZm0:RXhZgPlvjx4rhGQLvsd9/qE2X9Rvc0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Winlock also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Trojan.ShellStartup.FGW@ayxMx3gc
FireEyeGeneric.mg.774db116668b0df9
CAT-QuickHealRansom.Somhoveran.C8
McAfeeArtemis!774DB116668B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0043daac1 )
BitDefenderGen:Trojan.ShellStartup.FGW@ayxMx3gc
K7GWTrojan ( 0043daac1 )
Cybereasonmalicious.6668b0
TrendMicroMal_LockScreen
BitDefenderThetaAI:Packer.6C97740F21
ESET-NOD32Win32/LockScreen.AWI
APEXMalicious
AvastWin32:Agent-ATUS [Trj]
GDataGen:Trojan.ShellStartup.FGW@ayxMx3gc
KasperskyTrojan-Ransom.Win32.Gimemo.cdqu
AlibabaRansom:Win32/Gimemo.ccd47852
NANO-AntivirusTrojan.Win32.Gimemo.foalcc
AegisLabTrojan.Win32.Gimemo.j!c
RisingTrojan.LockScreen!1.AA76 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.ShellStartup.FGW@ayxMx3gc (B)
ComodoTrojWare.Win32.Ransom.Gimemo.OP@5rbubo
F-SecureTrojan.TR/Strictor.oiuya
DrWebTrojan.KillProc.44480
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.jc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusWin32.Outbreak
CyrenW32/ShellStartup.A.gen!Eldorado
AviraTR/Strictor.oiuya
Antiy-AVLTrojan[Ransom]/Win32.Gimemo.bdvq
MicrosoftRansom:Win32/Somhoveran.D!bit
ArcabitTrojan.ShellStartup.E736F3
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AhnLab-V3Malware/Win32.Generic.C2446793
ZoneAlarmTrojan-Ransom.Win32.Gimemo.cdqu
Acronissuspicious
VBA32Trojan-Ransom.Winlock.gen
MalwarebytesRansom.Winlock
PandaTrj/CI.A
TrendMicro-HouseCallMal_LockScreen
TencentWin32.Trojan.Gimemo.Agvd
MAXmalware (ai score=85)
FortinetW32/LockScreen.AW!tr
AVGWin32:Agent-ATUS [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.IM.d8e

How to remove Trojan-Ransom.Winlock?

Trojan-Ransom.Winlock removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment