Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Apr 04, 2016 | Updated Sep 15, 2017

Worm:Win32/Kalockan.A

Detected by Microsoft Defender Antivirus

Aliases: Trojan/Win32.Locky (AhnLab) TR/AD.Bublik.Y.amlj (Avira) W32/Trojan.LTHM-8977 (Command) Win32/Spy.Bebloh.K trojan (ESET) Malicious_Behavior.VEX.89 (Fortinet) Trojan.Inject (Ikarus) Trojan.Win32.Agent.ijew (Kaspersky) RDN/Trojan-FIZQ (McAfee) Troj/Shiotob-AR (Sophos) TSPY_BEBLOH.AAACM (Trend Micro)

Summary

Microsoft Defender Antivirus detects and removes this threat.

This threat is a proxy-data-stealing and information-stealing malware with backdoor capabilities. It allows a remote attacker to take control of your PC and steal personal information.

We have observed this threat being distributed as a malicious attachment to spam email.

Find out ways that malware can get on your PC.  

Use the following free Microsoft software to detect and remove this threat:

You should also run a full scan. A full scan might find hidden malware.

Get more help

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

If you’re using Windows XP, see our Windows XP end of support page.

Follow us