Trojan

Trojan.Winlock.D malicious file

Malware Removal

The Trojan.Winlock.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Winlock.D virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Winlock.D?


File Info:

crc32: 44908875
md5: 2cb07e3d9ae02b931b4482e5bdb0b4c5
name: 2CB07E3D9AE02B931B4482E5BDB0B4C5.mlw
sha1: 8def17fcc8fc64b005bac2316c13ff85e1a2f73f
sha256: d5cb99c759d403b3c5af6485a26d9c846c9328677714c173c14b8893cdfcd37c
sha512: c4a14f4d19bb1b550d499310470d701deb6467fb194b6207bae7e9087121db4cc815e0e337f35fe438d046fe78b2c9df16bbf1c9b02e1001d776754317f020d8
ssdeep: 3072:uDkCeLwz5ddyr7d1fobu6cp7KhBVHlTShzxh9utout7:uAXCW7zfozF6hz0oS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Horus Dakota Rocco Pakistani Rachmaninoff
InternalName: onf
FileVersion: 5.06.0002
CompanyName: Albania Sieglinda Jefferson Keynesian Hillel
Comments: Enfield June Wellesley Alec Hopi
ProductName: Olympic Metcalf
ProductVersion: 5.06.0002
FileDescription: Leonid Precambrian Sappho Constantine
OriginalFilename: onf.exe

Trojan.Winlock.D also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e4091 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Winlock.D
CylanceUnsafe
ZillyaTrojan.PornoAsset.Win32.22905
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/PornoAsset.9941a268
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.d9ae02
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.Winlock.D
MicroWorld-eScanTrojan.Winlock.D
Ad-AwareTrojan.Winlock.D
SophosML/PE-A + Mal/Behav-221
ComodoTrojWare.Win32.Agent.~rlk1@3zeflh
BitDefenderThetaAI:Packer.9E7117B020
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.ft
FireEyeGeneric.mg.2cb07e3d9ae02b93
EmsisoftTrojan.Winlock.D (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PornoAsset.tmr
AviraTR/Dropper.Gen
eGambitGeneric.Malware
KingsoftWin32.Troj.Undef.(kcloud)
GDataTrojan.Winlock.D
TACHYONRansom/W32.PornoAsset.328704
AhnLab-V3Trojan/Win32.VBKrypt.C74429
McAfeeArtemis!2CB07E3D9AE0
MAXmalware (ai score=99)
VBA32Trojan-Ransom.Winlock.2871
PandaGeneric Malware
TencentMalware.Win32.Gencirc.114bbc02
YandexTrojan.PornoAsset!RuQQ8wMlK5U
IkarusTrojan.Win32.LockScreen
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.IEW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Winlock.D?

Trojan.Winlock.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment