Ransom

Should I remove “Ransom.LockScreen”?

Malware Removal

The Ransom.LockScreen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.LockScreen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Detects Sandboxie through the presence of a library
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Ransom.LockScreen?


File Info:

crc32: 9AA3BCDA
md5: 0f394f34ea3bac8124dee81ce4834ef3
name: 0F394F34EA3BAC8124DEE81CE4834EF3.mlw
sha1: 32d6d57f73a09b61ff129ce5cdc048b8278e9ba5
sha256: 8be3d8ba1504f108c4dbeb864ab220aa7c7de47ddd2eb0d918c00a31ec1c776f
sha512: f54d73656f49a8aff5337841e9c9cb485dc52483a46a426f9cbc2fb9a08ec207ea20ccfb8a9b263ff2b46b6413a63a8ae2fa3e65d19555e9abc663c7fa22199a
ssdeep: 24576:NMD6lryKqx1LzvrBw7NDyiftgO/mCsKNZqUZHg5CmLdM/v5274wqlza:NzGvpzv27NmiftgGrZqUdhCdMsswqM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.LockScreen also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30360748
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4ea3ba
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.LGWPVL
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.30360748
NANO-AntivirusTrojan.Win32.Weenloc.ezdfuq
MicroWorld-eScanTrojan.GenericKD.30360748
TencentWin32.Trojan.Generic.Gvp
Ad-AwareTrojan.GenericKD.30360748
BitDefenderThetaGen:NN.ZexaF.34670.vPW@aqTKw7bc
FireEyeGeneric.mg.0f394f34ea3bac81
EmsisoftTrojan.GenericKD.30360748 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/WeenLoc.abfvn
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Weenloc.A
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKD.30360748
McAfeeArtemis!0F394F34EA3B
VBA32TScope.Malware-Cryptor.SB
MalwarebytesRansom.LockScreen
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:5qBfiyJlfwtMFoMFN6Qnew)
YandexTrojan.Agent!W5QczWz4zrM
IkarusTrojan.Win32.VMProtect
FortinetW32/Generik.LGWPVL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Weenloc.HgIASScA

How to remove Ransom.LockScreen?

Ransom.LockScreen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment