Malware

Win32:Locky-J [Trj] removal

Malware Removal

The Win32:Locky-J [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Locky-J [Trj] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Created network traffic indicative of malicious activity

Related domains:

jfphvgou.pw
wpad.local-net
buiiqnn.nl

How to determine Win32:Locky-J [Trj]?


File Info:

name: Locky
path: /opt/CAPEv2/storage/binaries/bc98c8b22461a2c2631b2feec399208fdc4ecd1cd2229066c2f385caa958daa3
crc32: AB35FD91
md5: b06d9dd17c69ed2ae75d9e40b2631b42
sha1: b606aaa402bfe4a15ef80165e964d384f25564e4
sha256: bc98c8b22461a2c2631b2feec399208fdc4ecd1cd2229066c2f385caa958daa3
sha512: 8e54aca4feb51611142c1f2bf303200113604013c2603eea22d72d00297cb1cb40a2ef11f5129989cd14f90e495db79bffd15bd6282ff564c4af7975b1610c1c
ssdeep: 3072:gzWgfLlUc7CIJ1tkZaQyjhOosc8MKi6KDXnLCtyAR0u1cZ86:gdLl4wkZa/UDiD7ukst1H6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19404D0BB715D8806FF75947640CC2A23DDE3E8B091ADDE23A68346E78C852DC58C9727
sha3_384: 5ba75cb7ea03696dacec1c7f8d4e039eeb8a18ad63d4673b8fbb832b45df010600ac3336b2a715e4eba1ef8a8dc2cf46
ep_bytes: 558bec6aff68c8d24000682576400064
timestamp: 2005-06-20 03:55:03

Version Info:

Comments:
CompanyName: FileSee.com
FileDescription:
FileVersion: 0.37.213.27
InternalName:
LegalCopyright: Intend (C) 2013
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: Lipreading Fenced
ProductVersion: 0.144.212.113
SpecialBuild:

Win32:Locky-J [Trj] also known as:

LionicTrojan.Win32.Locky.tn46
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
MicroWorld-eScanTrojan.GenericKD.3048400
FireEyeGeneric.mg.b06d9dd17c69ed2a
CAT-QuickHealRansom.Crowti.MUE.A4
ALYacTrojan.Ransom.LockyCrypt
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.1939
SangforRansom.Win32.Locky.d
K7AntiVirusTrojan ( 004dea2e1 )
AlibabaRansom:Win32/Locky.6507139d
K7GWTrojan ( 004dea2e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34266.lq0@aCnbRDi
CyrenW32/Trojan.MXJM-9187
SymantecRansom.Locky
ESET-NOD32Win32/Filecoder.Locky.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Locky-9659911-0
KasperskyTrojan-Ransom.Win32.Locky.d
BitDefenderTrojan.GenericKD.3048400
NANO-AntivirusTrojan.Win32.Dwn.efgxkj
SUPERAntiSpywareTrojan.Agent/Gen-Locky
AvastWin32:Locky-J [Trj]
TencentMalware.Win32.Gencirc.10b7d34e
Ad-AwareTrojan.GenericKD.3048400
TACHYONTrojan/W32.Yakes.184320.R
EmsisoftTrojan.GenericKD.3048400 (B)
ComodoTrojWare.Win32.Ransom.Locky.DB@6ae1qd
BaiduWin32.Trojan.Kryptik.qb
VIPREWin32.Malware!Drop
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionBehavesLike.Win32.Emotet.ch
SophosMal/Generic-R + Troj/Ransom-CGR
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Generic.cinbf
WebrootW32.Ransom.Locky
AviraTR/Agent.53465
Antiy-AVLTrojan/Generic.ASMalwS.172438D
KingsoftWin32.Troj.Generic.ac.(kcloud)
GridinsoftRansom.Win32.Locky.sd!s1
MicrosoftRansom:Win32/Locky.A
ViRobotTrojan.Win32.Z.Locky.184320.BB
GDataWin32.Trojan-Ransom.Locky.D
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Teslacrypt.1339F9E.X1654
Acronissuspicious
McAfeeGeneric.yk
MAXmalware (ai score=100)
VBA32BScope.TrojanDownloader.Talalpek
MalwarebytesRansom.Locky
ZonerTrojan.Win32.38770
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
RisingRansom.Locky!1.B657 (CLASSIC)
YandexTrojan.GenAsa!ffszjm+474I
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Filecoder.NFX!tr
AVGWin32:Locky-J [Trj]
Cybereasonmalicious.17c69e
PandaTrj/WLT.B
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32:Locky-J [Trj]?

Win32:Locky-J [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment