We checked some samples of {71257279-042B-371D-A1D3-FBF8D2FADFFA}.EXE and detected the file {71257279-042B-371D-A1D3-FBF8D2FADFFA}.EXE as threat.
Remove the {71257279-042B-371D-A1D3-FBF8D2FADFFA}.EXE file from your computer right now.
Removal tool: http://www.unhackme.com
Malware Analysis of {71257279-042B-371D-A1D3-FBF8D2FADFFA}.EXE
Full path on a computer: %Appdata%\{71257279-042B-371D-A1D3-FBF8D2FADFFA}.exe
Detected by UnHackMe:
{71257279-042B-371D-A1D3-FBF8D2FADFFA}.EXE
Default location: %Appdata%\{71257279-042B-371D-A1D3-FBF8D2FADFFA}.exe
Removal Results: Success
Number of reboot: 1
{71257279-042B-371D-A1D3-FBF8D2FADFFA}.EXE is known as:
Trojan.Filecoder.bq, W32.Trojan2.OACP, Trojan.Cryptolocker, CryptLocker.B, Win32.Ransom.HLV, Win.Trojan.Cryptolocker, Trojan-Ransom.Blocker.cfkz, Trojan.Blocker.Jn0NSGZ2ifk, Trojan.Agent.Gen-Ransom, Trojan.DownLoader10.47943, Trojan.Cryptolocker.mc (fs), Troj.Ransom-ACV, Trojan.Blocker.lrw, Trojan[Ransom].Blocker, Trojan.Crilock.A, Trojan.Agent.351744.F, W32.Trojan.HVNG-6757, Trojan.Blocker, Hoax.Blocker, Trojan.Ransomlock.ab, Win32.Filecoder.BQ, PE:Trojan.CryptoLocker.1.9E7C, Trojan-Ransom.CryptoLocker, W32.Blocker.CFKZ.tr
{71257279-042B-371D-A1D3-FBF8D2FADFFA}.EXE hash:
- MD5: 012d9088558072bc3103ab5da39ddd54
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\CryptoLocker: “”%Appdata%\{71257279-042B-371D-A1D3-FBF8D2FADFFA}.exe”"
- %Appdata%\{71257279-042B-371D-A1D3-FBF8D2FADFFA}.exe