Ransom

Ransom:AutoIt/LockScreen.D removal instruction

Malware Removal

The Ransom:AutoIt/LockScreen.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:AutoIt/LockScreen.D virus can do?

  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Attempts to restart the guest VM
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Attempts to modify browser security settings
  • Attempts to disable browser security warnings

Related domains:

edgedl.me.gvt1.com
update.googleapis.com
oppnetter.biz.ua

How to determine Ransom:AutoIt/LockScreen.D?


File Info:

crc32: 59E31ACD
md5: 87a2c411e878cca083a06d9ffeb581a2
name: 87A2C411E878CCA083A06D9FFEB581A2.mlw
sha1: 4b03ed55bd45e36469a0b373a0d32f964d51c177
sha256: 3e931d6d7be99aa38831159046019355e3ca16f377ba8178a86d2caac7d25a0a
sha512: e9dcc59300e9c41b13823e3be4b0ee1312be7e70088a30c73f1397dc4fc893fdc00d9ee38e8b459a84557fed702ab9204476168553c84ed3db81c4407c83bdf1
ssdeep: 24576:bRmJkqoQrilOIQ+yMxyNypYENNMw2mlcKtbby:YJXoQryTiMxyNypYSqwBesby
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 0
FileVersion: 3, 3, 8, 0
FileDescription:
Translation: 0x0809 0x04b0

Ransom:AutoIt/LockScreen.D also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0047e7591 )
LionicTrojan.Win32.Autoit.j!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.41809
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.143411
SangforRansom.Win32.Autoit.v
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/LockScreen.43d32a4c
K7GWTrojan ( 0047e7591 )
Cybereasonmalicious.5bd45e
SymantecTrojan.Gen
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:AutoIt-BPS [Trj]
KasperskyTrojan-Ransom.Win32.Autoit.v
NANO-AntivirusTrojan.Win32.Autoit.ecjjdi
TencentWin32.Trojan.Autoit.Ecak
SophosMal/Generic-S
ComodoMalware@#as2accg6s5lk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.dc
FireEyeGeneric.mg.87a2c411e878cca0
AviraHEUR/AGEN.1116021
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASCommon.168
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:AutoIt/LockScreen.D
Acronissuspicious
McAfeeArtemis!87A2C411E878
MAXmalware (ai score=95)
VBA32Trojan.Autoit.F
PandaTrj/CI.A
RisingTrojan.Obfus/Autoit!1.BEDE (CLASSIC)
MaxSecureTrojan.Autoit.AZA
FortinetW32/Autoit.V!tr
AVGWin32:AutoIt-BPS [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Worm.AutoIt.HgIASOcA

How to remove Ransom:AutoIt/LockScreen.D?

Ransom:AutoIt/LockScreen.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment