Ransom

Ransom:Win32/LockScreen.AO removal guide

Malware Removal

The Ransom:Win32/LockScreen.AO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/LockScreen.AO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/LockScreen.AO?


File Info:

crc32: F0EDC276
md5: 0ffa72887e010c76a23e8c1d8aa55d52
name: 0FFA72887E010C76A23E8C1D8AA55D52.mlw
sha1: 68483bf316d0bb339332d68e9d1eb07d16dbce8d
sha256: 3650d6fff966a3d1c7d2e423826b30c96fe653d36a93075dd64063c988768935
sha512: 55e6688558e740cd020f98629f6deea06008d0c04360de373a3ccc57dfbedde0d9d87c0f1527c7b2ae4226d018ffbd44425e6e1286efb488a016467da2a527e1
ssdeep: 6144:v9MplDtkOxYjVoMp37vZ2AmFY/ctq5sMoEKBe4Vjv/HsKfo+48MSjm:voDtkOxYjxTZLmFYktQsMoN5vUMo+48
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/LockScreen.AO also known as:

BkavW32.MosquitoQKB.Fam.Trojan
DrWebTrojan.Winlock.2741
MicroWorld-eScanGen:Variant.Ser.Razy.10733
FireEyeGeneric.mg.0ffa72887e010c76
ALYacGen:Variant.Ser.Razy.10733
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Ser.Razy.10733
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34590.wmGfaOpFedgc
CyrenW32/FakeAlert.MW.gen!Eldorado
SymantecPacked.Generic.318
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Agent-1047960
KasperskyTrojan-Ransom.Win32.Gimemo.vc
AlibabaRansom:Win32/LockScreen.5ede7c51
NANO-AntivirusTrojan.Win32.Gimemo.bwsfv
ViRobotTrojan.Win32.A.Gimemo.363008.A[UPX]
AegisLabTrojan.Win32.Gimemo.j!c
TencentWin32.Trojan.Gimemo.Lju
Ad-AwareGen:Variant.Ser.Razy.10733
EmsisoftGen:Variant.Ser.Razy.10733 (B)
ComodoSuspicious@#1dxndqxut15lw
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Gimemo.Win32.96
TrendMicroTROJ_CRYPTR.SMKV
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
SophosMal/Generic-R + Mal/Zbot-EZ
IkarusTrojan-Ransom.PornoBlocker
JiangminTrojan/Gimemo.hj
eGambitGeneric.Malware
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/LockScreen.AO
ArcabitTrojan.Ser.Razy.D29ED
SUPERAntiSpywareTrojan.Agent/Gen-DitherC
ZoneAlarmTrojan-Ransom.Win32.Gimemo.vc
GDataGen:Variant.Ser.Razy.10733
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R2835
McAfeeArtemis!0FFA72887E01
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
PandaGeneric Malware
ESET-NOD32Win32/LockScreen.YL
TrendMicro-HouseCallTROJ_CRYPTR.SMKV
RisingRansom.LockScreen!8.83D (CLOUD)
YandexTrojan.GenAsa!8c3/CbzS8Tg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1720719.susgen
FortinetW32/Krap.A!tr
AVGFileRepMalware
Cybereasonmalicious.87e010
Qihoo-360Win32/Ransom.Gimemo.HgIASOYA

How to remove Ransom:Win32/LockScreen.AO?

Ransom:Win32/LockScreen.AO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment