Ransom

Ransom:Win32/LockScreen.BS removal tips

Malware Removal

The Ransom:Win32/LockScreen.BS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/LockScreen.BS virus can do?

  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/LockScreen.BS?


File Info:

crc32: CCEBA182
md5: 31ecd0987a2a949ee59590b8c341106c
name: 31ECD0987A2A949EE59590B8C341106C.mlw
sha1: b25ee6d5b45144c492a9cc144d3f57d65c05ab64
sha256: 7037ff7a043dce03850ab803a81ad372dbe1a70a17139e28f8f6fd71916abd78
sha512: 27fc443c94e4f829e69c4499206575551f1e4ceeaec631bfed4c883c26a07bd8f063da9226f74a6b86048126967c782ad0ea7f09b299cac120c6a519eebcbb86
ssdeep: 1536:FwUqtQ2DDR76rqvMU6oguM1KF9Q1nqYtrCbnb8OohA:YtJ6rq0G5M1QoqYtObnb8OohA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/LockScreen.BS also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00092b5f1 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.65
CynetMalicious (score: 100)
ALYacGen:Variant.Jacard.202049
CylanceUnsafe
ZillyaTrojan.SMSer.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/LockScreen.843e3984
K7GWTrojan ( 00092b5f1 )
Cybereasonmalicious.87a2a9
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.F
APEXMalicious
AvastWin32:Delfcrypt-AI [Trj]
KasperskyTrojan-Ransom.Win32.ChameleonUnlicence.p
BitDefenderGen:Variant.Jacard.202049
NANO-AntivirusTrojan.Win32.Winlock.hqqd
ViRobotTrojan.Win32.A.ChameleonUnlicence.97280
MicroWorld-eScanGen:Variant.Jacard.202049
TencentMalware.Win32.Gencirc.10c250e1
Ad-AwareGen:Variant.Jacard.202049
SophosMal/Generic-S
ComodoTrojWare.Win32.Trojan.Agent.~HRL@1e9zoi
BitDefenderThetaGen:NN.ZelphiF.34678.fGW@aiGJXKec
VIPREBehavesLike.Win32.Malware.wlk (mx-v)
McAfee-GW-EditionGenericR-HQT!31ECD0987A2A
FireEyeGeneric.mg.31ecd0987a2a949e
EmsisoftGen:Variant.Jacard.202049 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/SMSer.ae
AviraHEUR/AGEN.1122028
eGambitGeneric.Malware
MicrosoftRansom:Win32/LockScreen.BS
ArcabitTrojan.Jacard.D31541
AegisLabTrojan.Win32.ChameleonUnlicence.j!c
ZoneAlarmTrojan-Ransom.Win32.ChameleonUnlicence.p
GDataGen:Variant.Jacard.202049
AhnLab-V3Trojan/Win32.Agent.C1986796
Acronissuspicious
McAfeeGenericR-HQT!31ECD0987A2A
MAXmalware (ai score=99)
VBA32BScope.Trojan.Downloader
PandaGeneric Malware
RisingTrojan.Spy.Win32.Undef.hi (CLASSIC)
YandexTrojan.GenAsa!T5b5pf7J0Qk
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Generic.AC.2104784
AVGWin32:Delfcrypt-AI [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.PornoBlocker.HwUBEpsA

How to remove Ransom:Win32/LockScreen.BS?

Ransom:Win32/LockScreen.BS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment