Ransom

Ransom:Win32/LockScreen.S removal instruction

Malware Removal

The Ransom:Win32/LockScreen.S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/LockScreen.S virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (13 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

pornozud.com
www.bing.com
cbu01.alicdn.com
js.users.51.la
img.dadiziyuan.net
ocsp.digicert.com
ocsp.globalsign.com
ocsp2.globalsign.com
statuse.digitalcertvalidation.com
ia.51.la
push.zhanzhang.baidu.com
crl3.digicert.com

How to determine Ransom:Win32/LockScreen.S?


File Info:

crc32: 1C86970B
md5: 057986dfd9217e9eec167bee31dd5be8
name: 057986DFD9217E9EEC167BEE31DD5BE8.mlw
sha1: cdbe8b3d4fa3030cc34cfa28d79059181a0b1b46
sha256: 3e5e9c5e829ae72962717084a6075b5b4cd3b6722f2e6581da7974b26d68114d
sha512: d60054d21d8d4e4612203197f6ad287ead4a819b86c643babdd3d195bb1bf49016a7ae29d8587fcf8e7c1f99b8c4b9fdc16cdacb91cc04d81f5fe412e4defeb0
ssdeep: 6144:n3l9JBvc6ssU3Elo5vE9B7OMTsghpAnfOZrb8vYXBlYAoF1F0pa5j:3l9/vc6sBso+7OUEnfLsBJoFEpkj
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Ransom:Win32/LockScreen.S also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e4091 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.5465
CynetMalicious (score: 100)
ALYacBackdoor.Generic.449205
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.129
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/LockScreen.c8120a8d
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.fd9217
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LockScreen.VP
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Gimemo.cdpb
BitDefenderBackdoor.Generic.449205
NANO-AntivirusTrojan.Win32.Gimemo.cqtvn
MicroWorld-eScanBackdoor.Generic.449205
TencentWin32.Trojan.Gimemo.cbx
Ad-AwareBackdoor.Generic.449205
SophosML/PE-A
ComodoTrojWare.Win32.Ransom.Gimemo.tz@4nu0ar
BitDefenderThetaGen:NN.ZelphiCO.34686.EiW@aiTzA8b
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
FireEyeGeneric.mg.057986dfd9217e9e
EmsisoftBackdoor.Generic.449205 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Gimemo.asn
AviraTR/Patched.Ren.Gen
eGambitGeneric.Malware
MicrosoftRansom:Win32/LockScreen.S
ArcabitBackdoor.Generic.D6DAB5
AegisLabTrojan.Win32.Gimemo.4!c
GDataBackdoor.Generic.449205
TACHYONTrojan/W32.DP-Gimemo.499712
AhnLab-V3Trojan/Win32.PornoBlocker.C85489
McAfeeArtemis!057986DFD921
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Stealer
MalwarebytesMalware.AI.3924704969
PandaGeneric Malware
RisingRansom.Gimemo!8.306 (CLOUD)
YandexTrojan.Gimemo!jJubrsujkZs
IkarusTrojan-Ransom.PornoBrick
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/LockScreen.VP!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/LockScreen.S?

Ransom:Win32/LockScreen.S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment