Ransom Trojan

Trojan.Ransom.ScreenLocker malicious file

Malware Removal

The Trojan.Ransom.ScreenLocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.ScreenLocker virus can do?

  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ransom.ScreenLocker?


File Info:

crc32: 512C00D5
md5: 5d7455637c1ba0bdc6a7345a382e35a0
name: 5D7455637C1BA0BDC6A7345A382E35A0.mlw
sha1: 190518390b5ba7497aa6b1d74c54c8594229cc4f
sha256: da8120e106b83a7e36ae34801cb5b41a98c486c7f5496c43208bbfe9bb2c047c
sha512: 312fbabb07dc4ea2b3b80886a8044b0d2fd6f55772b0bda11df75fa5e71bc1797b3955a8f3e8668aa48ebe818889080c3d7f41f70604f904d1b4d26126111c24
ssdeep: 3072:aGbHwx3GsAFyQbXO0kwXmFRqAh+7QouCv8BATTy+zL9GwqRlcBapeEdmIMyXs:aG7u6jrkwvKaXR0cyYLF6lcBapBdd8
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Ransom.ScreenLocker also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0039911e1 )
Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Fullscreen-7347612-0
CAT-QuickHealRansom.Weenloc.A8
ALYacTrojan.Ransom.ScreenLocker
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Generic.5848174
K7GWTrojan ( 0039911e1 )
Cybereasonmalicious.37c1ba
BaiduWin32.Trojan.LockScreen.b
SymantecTrojan.Ransomlock
ESET-NOD32a variant of Win32/LockScreen.AGU
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AlibabaRansom:Win32/Blocker.9c8be9ae
NANO-AntivirusTrojan.Win32.Fullscreen.crnep
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
MicroWorld-eScanTrojan.Generic.5848174
Ad-AwareTrojan.Generic.5848174
ComodoTrojWare.Win32.Ransom.Fullscreen.fgt@4t6ar8
BitDefenderThetaGen:NN.ZelphiF.34688.jmGfaqFqy9pI
VIPRETrojan.Win32.Birele.mby (v)
FireEyeGeneric.mg.5d7455637c1ba0bd
EmsisoftTrojan.Generic.5848174 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Fullscreen.ak
AviraDR/Delphi.Gen4
KingsoftHeur.SSC.5536.1216.(kcloud)
ArcabitTrojan.Generic.D593C6E
AegisLabTrojan.Win32.Blocker.j!c
GDataTrojan.Generic.5848174
TACHYONRansom/W32.DP-PornoAsset.407040
AhnLab-V3Trojan/Win32.Winlock.C134008
MAXmalware (ai score=100)
MalwarebytesRansom.Filecoder
TrendMicro-HouseCallRansom_WINLOCK.SM
TencentTrojan-Ransom.Win32.Blocker.jzec
YandexTrojan.GenAsa!EkA5wRxKoJY
IkarusTrojan-Ransom.Birele
FortinetW32/LockScreen.AGU!tr
PandaTrj/Genetic.gen

How to remove Trojan.Ransom.ScreenLocker?

Trojan.Ransom.ScreenLocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment