Ransom

Ransom:Win32/LockScreen.BL information

Malware Removal

The Ransom:Win32/LockScreen.BL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/LockScreen.BL virus can do?

  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/LockScreen.BL?


File Info:

crc32: 62B35F36
md5: d50d9a71793732fee71719dda405ab83
name: D50D9A71793732FEE71719DDA405AB83.mlw
sha1: 85c6655285ee1b930926591ca229bbcc0f6ce04a
sha256: 95dbc3a849053e1d2c7f3e96849d123c3ea1aa51fc4479c62576556aedc83edb
sha512: 5026daa8f9078799a1035410ca26320f683427958fe07e823a24b46a700c40d4d8a9f1dc8bf68dd02a868cdb6bab835735234794e6c0147626724e32b8eb46a3
ssdeep: 1536:ms0q/QCz+p8ZiTMavNsnBxDGQmxE0bb8:D3KpSi9NCTmxEa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/LockScreen.BL also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.Winlock.origin
McAfeeArtemis!D50D9A717937
CylanceUnsafe
ZillyaTrojan.LockScreen.Win32.10019
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
CyrenW32/Risk.NELJ-5801
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.WG
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.DP.dGW@aODeVUdc
NANO-AntivirusTrojan.Win32.Winlock.exlapg
MicroWorld-eScanGen:Trojan.Heur.DP.dGW@aODeVUdc
TencentWin32.Trojan.Generic.Woft
Ad-AwareGen:Trojan.Heur.DP.dGW@aODeVUdc
SophosML/PE-A + Mal/DownLdr-AJ
BitDefenderThetaAI:Packer.297F991C1F
VIPREBehavesLike.Win32.Malware.wlk (mx-v)
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.d50d9a71793732fe
EmsisoftGen:Trojan.Heur.DP.dGW@aODeVUdc (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Bumat.Gen
AviraDR/Delphi.Gen8
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/LockScreen.BL
GDataGen:Trojan.Heur.DP.dGW@aODeVUdc
VBA32Trojan.WinLock.9265
MAXmalware (ai score=99)
MalwarebytesMalware.AI.3924704969
PandaTrj/StartPage.DAW
RisingRansom.LockScreen!8.83D (CLOUD)
YandexTrojan.GenAsa!idcfAQSq9AU
IkarusTrojan-Ransom.PornoBrick
FortinetW32/PornoBlocker.AJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/LockScreen.BL?

Ransom:Win32/LockScreen.BL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment