Malware

MSIL/LockScreen.O removal

Malware Removal

The MSIL/LockScreen.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/LockScreen.O virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Anomalous binary characteristics

How to determine MSIL/LockScreen.O?


File Info:

name: 490B1CD3A275DC265B6A.mlw
path: /opt/CAPEv2/storage/binaries/8f67bcfee460462fd9e198e8b5e26351d8f18f2c872a2281d0e9421b76ec5785
crc32: DE122F1D
md5: 490b1cd3a275dc265b6a71af11634379
sha1: a96a319fe6c888450bfb966d26615f79dfde4daa
sha256: 8f67bcfee460462fd9e198e8b5e26351d8f18f2c872a2281d0e9421b76ec5785
sha512: c3c0244e6742139103a3081c06519dce867d6647038f6f614d7712eb7d846d08426e5c57c75f7875d4e273333bb28520e4c27a2e9bbded70f11ccb8516d14d24
ssdeep: 1536:dM7Q4SqJUVMvbg67ItjpOoqSYn9lKHKF7G7:dM72ejItjpOAYnPKqc7
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T14C636C35BB6AAE2ED275EBF69071A3570771C2770401F28A9CF984FA9D0D7D00A93193
sha3_384: 476984120e34192bfeec5bc74969b092e776ef996cd6d2876814ce58015c63dc3323e08619bee34696f86acfe6795d96
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2012-01-10 07:42:00

Version Info:

Translation: 0x0000 0x04b0
Comments: wersvc
CompanyName: Microsoft
FileDescription: wersvc
FileVersion: 1.0.0.0
InternalName: wersvc.exe
LegalCopyright: Copyright © Microsoft 2011
OriginalFilename: wersvc.exe
ProductName: wersvc
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/LockScreen.O also known as:

MicroWorld-eScanTrojan.GenericKD.5546984
FireEyeGeneric.mg.490b1cd3a275dc26
McAfeeArtemis!490B1CD3A275
CylanceUnsafe
K7AntiVirusTrojan ( 0033e4f81 )
AlibabaTrojan:MSIL/LockScreen.0c98ec7a
K7GWTrojan ( 0033e4f81 )
Cybereasonmalicious.3a275d
ArcabitTrojan.Generic.D54A3E8
CyrenW64/MSIL_Agent.CDE.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/LockScreen.O
TrendMicro-HouseCallTROJ_GEN.R002H0CKP21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.5546984
AvastWin64:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.11498f2d
Ad-AwareTrojan.GenericKD.5546984
EmsisoftTrojan.GenericKD.5546984 (B)
DrWebTrojan.MulDrop19.6706
ZillyaTrojan.LockScreen.Win32.9885
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.MSIL.LockScreen
AviraTR/LockScreen.shcqf
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwFH.3CEA4C2
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
APEXMalicious
GDataTrojan.GenericKD.5546984
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4789429
ALYacTrojan.GenericKD.5546984
MalwarebytesMalware.AI.921684878
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/LockScreen.O!tr
AVGWin64:MalwareX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove MSIL/LockScreen.O?

MSIL/LockScreen.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment