Ransom

Ransom:Win32/LockScreen.BZ removal tips

Malware Removal

The Ransom:Win32/LockScreen.BZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/LockScreen.BZ virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ransom:Win32/LockScreen.BZ?


File Info:

crc32: 30E2821B
md5: 5f35d29377e680dfd1620170ae89bef9
name: 5F35D29377E680DFD1620170AE89BEF9.mlw
sha1: f926ada51bfa1ad7064296ebbd26e17b2204b300
sha256: d5be1010a755b34995fdc05b966360eaaa01ffa7fb23aa6e753177440cf98885
sha512: beb0a7531416aa321f21f3547c9be526b8cc55df28aea4512fecd285c4f3acd4f0577fff235a4dddbeb81be4ff030ad0cd329407bb0fe76933c86b85d359a764
ssdeep: 3072:d91sOnt/1lw56sucnkL99D9NsKWTzJLnbGShJ9h58pPyRACtVZRKIBt4FD+BCkK:RsK20snERsKWBLbGSV81S1bKst4FGKG
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/LockScreen.BZ also known as:

DrWebTrojan.Winlock.5790
CynetMalicious (score: 100)
CAT-QuickHealRansom.Weenloc.A8
ALYacGen:Variant.Barys.673
ZillyaTrojan.PornoAsset.Win32.23257
SangforTrojan.Win32.Elzob.fr1616
AlibabaRansom:Win32/LockScreen.fe4bb87a
Cybereasonmalicious.377e68
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.AHR
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Birele.fdj
BitDefenderGen:Variant.Barys.673
NANO-AntivirusTrojan.Win32.Winlock.edmgiy
MicroWorld-eScanGen:Variant.Barys.673
Ad-AwareGen:Variant.Barys.673
SophosMal/Generic-S (PUA)
ComodoMalware@#nex9xyr176wd
BitDefenderThetaGen:NN.ZelphiF.34738.omGfa8cfGZic
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
FireEyeGen:Variant.Barys.673
EmsisoftGen:Variant.Barys.673 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1105487
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.147FC7
MicrosoftRansom:Win32/LockScreen.BZ
GDataGen:Variant.Barys.673
McAfeeArtemis!5F35D29377E6
VBA32Hoax.Birele
PandaGeneric Malware
RisingWorm.Pahooka!1.BC8B (CLASSIC)
IkarusTrojan-Ransom.Birele
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Birele.FDJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/LockScreen.BZ?

Ransom:Win32/LockScreen.BZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment